VYPR

Checkmk

by Checkmk

Source repositories

CVEs (123)

  • CVE-2024-47094MedNov 29, 2024
    risk 0.36cvss 5.5epss 0.00

    Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets to be written to web log files accessible to local site users.

  • CVE-2022-48317MedFeb 20, 2023
    risk 0.36cvss 5.6epss 0.00

    Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when communicating with the RestAPI.

  • CVE-2026-3103MedMar 4, 2026
    risk 0.35cvss 5.4epss 0.00

    A logic error in the remove_password() function in Checkmk GmbH's Checkmk versions <2.4.0p23, <2.3.0p43, and 2.2.0 (EOL) allows a low-privileged user to cause data loss.

  • CVE-2025-64999MedFeb 26, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker that can manipulate a host's check output to inject malicious JavaScript into the Synthetic Monitoring HTML logs, which can then be accessed via a crafted…

  • CVE-2025-58122MedNov 18, 2025
    risk 0.35cvss 5.4epss 0.00

    Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notification parameters via the REST API, which could lead to unauthorized actions or information disclosure.

  • CVE-2025-58121MedNov 18, 2025
    risk 0.35cvss 5.4epss 0.00

    Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows low-privileged users to perform unauthorized actions or obtain sensitive information

  • CVE-2025-39664MedOct 9, 2025
    risk 0.35cvss 6.5epss 0.01

    Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define the storage location of report file pairs beyond their intended root directory.

  • CVE-2024-13722MedFeb 4, 2025
    risk 0.35cvss 5.4epss 0.01

    The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated…

  • CVE-2024-28831MedJun 25, 2024
    risk 0.35cvss 5.4epss 0.00

    Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injecting HTML elements into some user input fields that are shown in a confirmation pop-up.

  • CVE-2023-23548MedAug 1, 2023
    risk 0.35cvss 5.4epss 0.00

    Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30.

  • CVE-2022-48320MedFeb 20, 2023
    risk 0.35cvss 5.4epss 0.00

    Cross-site Request Forgery (CSRF) in Tribe29's Checkmk <= 2.1.0p17, Checkmk <= 2.0.0p31, and all versions of Checkmk 1.6.0 (EOL) allow an attacker to add new visual elements to multiple pages.

  • CVE-2022-24566MedFeb 24, 2022
    risk 0.35cvss 5.4epss 0.01

    In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when shown as condition, which can result in Cross Site Scripting (XSS).

  • CVE-2022-24565MedFeb 24, 2022
    risk 0.35cvss 5.4epss 0.01

    Checkmk <=2.0.0p19 Fixed in 2.0.0p20 and Checkmk <=1.6.0p27 Fixed in 1.6.0p28 are affected by a Cross Site Scripting (XSS) vulnerability. The Alias of a site was not properly escaped when shown as condition for notifications.

  • CVE-2021-36563MedJul 26, 2021
    risk 0.35cvss 5.4epss 0.02

    The CheckMK management web console (versions 1.5.0 to 2.0.0) does not sanitise user input in various parameters of the WATO module. This allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side…

  • CVE-2026-15227MedJul 31, 2026
    risk 0.34cvss —epss 0.00

    Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.

  • CVE-2026-33457MedApr 10, 2026
    risk 0.34cvss 6.3epss 0.00

    Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted service name parameter due to insufficient sanitization of the service description value.

  • CVE-2026-33455MedApr 10, 2026
    risk 0.34cvss 6.3epss 0.00

    Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input sanitization in search filter plugins.

  • CVE-2026-24095MedFeb 9, 2026
    risk 0.34cvss —epss 0.00

    Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its URL, bypassing the intended "Access analyze…

  • CVE-2025-65000MedDec 18, 2025
    risk 0.34cvss 5.3epss 0.00

    SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of Checkmk 2.3.0. This potentially allowed unauthorized triggering of predefined alert handlers on hosts where the handler was…

  • CVE-2025-3506MedMay 8, 2025
    risk 0.34cvss 5.3epss 0.00

    Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 and <Checkmk 2.4.0b6 allows attacker to access files that could contain secrets.

Page 4 of 7