VendorsZABBIXfrontendall versions
Vulnerabilities

ZABBIX Frontend

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2022-43515
X-Forwarded-For header is active by default causes access to Zabbix sites in maintenance mode
Published 2022-12-12 · Modified
9.8EPSS 0.012
CVE-2023-32725
Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget.
Published 2023-12-18 · Modified
9.6EPSS 0.008
CVE-2025-27232
Frontend arbitrary file read in oauth.authorize action
Published 2025-12-01 · Analyzed
6.8EPSS 0.003
CVE-2025-49643
Frontend DoS vulnerability due to asymmetric resource consumption
Published 2025-12-01 · Analyzed
6.5EPSS 0.003
CVE-2023-29457
Insufficient validation of Action form input fields
Published 2023-07-13 · Modified
6.3EPSS 0.006
CVE-2023-29455
Reflected XSS in several fields of graph form
Published 2023-07-13 · Modified
6.1EPSS 0.006
CVE-2023-30958
DOM XSS in Developer mode dashboard via redirect GET parameter
Published 2023-08-03 · Modified
6.1EPSS 0.004
CVE-2023-29456
Inefficient URL schema validation
Published 2023-07-13 · Modified
5.7EPSS 0.006
CVE-2023-29454
Persistent XSS in the user form
Published 2023-07-13 · Modified
5.4EPSS 0.006
CVE-2022-24349
Reflected XSS in action configuration window of Zabbix Frontend
Published 2022-03-09 · Modified
4.6EPSS 0.012
CVE-2022-24917
Reflected XSS in service configuration window of Zabbix Frontend
Published 2022-03-09 · Modified
4.4EPSS 0.012
CVE-2022-24919
Reflected XSS in graph configuration window of Zabbix Frontend
Published 2022-03-09 · Modified
4.4EPSS 0.012
CVE-2022-24918
Reflected XSS in item configuration window of Zabbix Frontend
Published 2022-03-09 · Modified
4.4EPSS 0.012