Centreon
by Centreon
Source repositories
CVEs (130)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-39988 | Med | 0.35 | 5.4 | 0.01 | Oct 6, 2022 | A cross-site scripting (XSS) vulnerability in Centreon 22.04.0 allows attackers to execute arbitrary web script or HTML via a crafted payload injected into the Service>Templates service_alias parameter. | ||
| CVE-2022-36194 | Med | 0.35 | 5.4 | 0.01 | Aug 29, 2022 | Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted payload into the name parameter. | ||
| CVE-2021-28054 | Med | 0.35 | 5.4 | 0.01 | Jul 16, 2021 | An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A Stored Cross-Site Scripting (XSS) issue in "Configuration > Hosts" allows remote authenticated users to inject arbitrary web script or HTML via the Alias parameter. | ||
| CVE-2021-27676 | Med | 0.35 | 5.4 | 0.01 | May 26, 2021 | Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Description) and dep_name (Dependency Name) parameters are vulnerable to stored XSS. A user has to log in and go to the Configuration > Notifications > Hosts page. | ||
| CVE-2021-28055 | Med | 0.35 | 6.5 | 0.01 | Apr 15, 2021 | An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user. | ||
| CVE-2025-12519 | Med | 0.34 | 5.3 | 0.00 | Jan 5, 2026 | Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not Properly Constrained by ACLs, resulting in Information Disclosure like downtime or acknowledgement configurations. This issue… | ||
| CVE-2022-3827 | Med | 0.34 | 6.3 | 0.01 | Nov 2, 2022 | A vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the file formContactGroup.php of the component Contact Groups Form. The manipulation of the argument cg_id leads to sql injection. The attack can be initiated… | ||
| CVE-2024-47863 | Med | 0.33 | 6.2 | 0.01 | Nov 22, 2024 | An issue was discovered in Centreon Web 24.10.x before 24.10.0, 24.04.x before 24.04.8, 23.10.x before 23.10.18, 23.04.x before 23.04.23, and 22.10.x before 22.10.26. A stored XSS was found in the user configuration contact name field. This form is only accessible to… | ||
| CVE-2019-16195 | Med | 0.33 | 6.1 | 0.01 | Nov 26, 2019 | Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields. | ||
| CVE-2022-40044 | Med | 0.28 | 5.4 | 0.01 | Sep 26, 2022 | Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted… | ||
| CVE-2019-17105 | Med | 0.28 | 5.3 | 0.02 | Oct 8, 2019 | The token generator in index.php in Centreon Web before 2.8.27 is predictable. | ||
| CVE-2015-7672 | Med | 0.28 | 5.4 | 0.01 | Sep 7, 2017 | Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27). | ||
| CVE-2020-10945 | Med | 0.21 | 4.3 | 0.01 | May 27, 2020 | Centreon before 19.10.7 exposes Session IDs in server responses. | ||
| CVE-2019-13024 | Hig | 0.06 | 8.8 | 0.32 | Jul 1, 2019 | Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the database, and execute it… | ||
| CVE-2008-1119 | 0.04 | — | 0.08 | Mar 3, 2008 | Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter. | |||
| CVE-2007-6485 | 0.04 | — | 0.11 | Dec 20, 2007 | Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary PHP code via a URL in the fileOreonConf parameter to (1) MakeXML.php or (2) MakeXML4statusCounter.php in include/monitoring/engine/. | |||
| CVE-2011-4431 | 0.03 | — | 0.06 | Nov 10, 2011 | Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commands via a .. (dot dot) in the command_name parameter. | |||
| CVE-2010-1301 | 0.03 | — | 0.03 | Apr 7, 2010 | SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via the host_id parameter. | |||
| CVE-2008-1178 | 0.03 | — | 0.05 | Mar 6, 2008 | Directory traversal vulnerability in include/doc/index.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2008-1119. | |||
| CVE-2021-37556 | Hig | 0.02 | 8.8 | 0.27 | Aug 3, 2021 | A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/reporting/dashboard/csvExport/csv_HostGroupLogs.php start and end… |
- risk 0.35cvss 5.4epss 0.01
A cross-site scripting (XSS) vulnerability in Centreon 22.04.0 allows attackers to execute arbitrary web script or HTML via a crafted payload injected into the Service>Templates service_alias parameter.
- risk 0.35cvss 5.4epss 0.01
Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted payload into the name parameter.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A Stored Cross-Site Scripting (XSS) issue in "Configuration > Hosts" allows remote authenticated users to inject arbitrary web script or HTML via the Alias parameter.
- risk 0.35cvss 5.4epss 0.01
Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Description) and dep_name (Dependency Name) parameters are vulnerable to stored XSS. A user has to log in and go to the Configuration > Notifications > Hosts page.
- risk 0.35cvss 6.5epss 0.01
An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user.
- risk 0.34cvss 5.3epss 0.00
Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not Properly Constrained by ACLs, resulting in Information Disclosure like downtime or acknowledgement configurations. This issue…
- risk 0.34cvss 6.3epss 0.01
A vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the file formContactGroup.php of the component Contact Groups Form. The manipulation of the argument cg_id leads to sql injection. The attack can be initiated…
- risk 0.33cvss 6.2epss 0.01
An issue was discovered in Centreon Web 24.10.x before 24.10.0, 24.04.x before 24.04.8, 23.10.x before 23.10.18, 23.04.x before 23.04.23, and 22.10.x before 22.10.26. A stored XSS was found in the user configuration contact name field. This form is only accessible to…
- risk 0.33cvss 6.1epss 0.01
Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.
- risk 0.28cvss 5.4epss 0.01
Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted…
- risk 0.28cvss 5.3epss 0.02
The token generator in index.php in Centreon Web before 2.8.27 is predictable.
- risk 0.28cvss 5.4epss 0.01
Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27).
- risk 0.21cvss 4.3epss 0.01
Centreon before 19.10.7 exposes Session IDs in server responses.
- risk 0.06cvss 8.8epss 0.32
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the database, and execute it…
- CVE-2008-1119Mar 3, 2008risk 0.04cvss —epss 0.08
Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter.
- CVE-2007-6485Dec 20, 2007risk 0.04cvss —epss 0.11
Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary PHP code via a URL in the fileOreonConf parameter to (1) MakeXML.php or (2) MakeXML4statusCounter.php in include/monitoring/engine/.
- CVE-2011-4431Nov 10, 2011risk 0.03cvss —epss 0.06
Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commands via a .. (dot dot) in the command_name parameter.
- CVE-2010-1301Apr 7, 2010risk 0.03cvss —epss 0.03
SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via the host_id parameter.
- CVE-2008-1178Mar 6, 2008risk 0.03cvss —epss 0.05
Directory traversal vulnerability in include/doc/index.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2008-1119.
- risk 0.02cvss 8.8epss 0.27
A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/reporting/dashboard/csvExport/csv_HostGroupLogs.php start and end…
Page 5 of 7