VYPR

Checkmk

by Checkmk

Source repositories

CVEs (116)

  • CVE-2024-6747MedOct 10, 2024
    risk 0.34cvss 5.3epss 0.00

    Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to get potentially sensitive data

  • CVE-2024-6163MedJul 8, 2024
    risk 0.34cvss 5.3epss 0.01

    Certain http endpoints of Checkmk in Checkmk < 2.3.0p10 < 2.2.0p31, < 2.1.0p46, <= 2.0.0p39 allows remote attacker to bypass authentication and access data

  • CVE-2022-48318MedFeb 20, 2023
    risk 0.34cvss 5.3epss 0.00

    No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which may lead to unintended information disclosure through automatically generated user specific tags within Rest API documentation.

  • CVE-2024-38858MedSep 2, 2024
    risk 0.33cvss 6.1epss 0.00

    Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.

  • CVE-2024-28832MedJun 25, 2024
    risk 0.31cvss 4.8epss 0.00

    Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.

  • CVE-2024-2380MedApr 5, 2024
    risk 0.30cvss 4.6epss 0.00

    Stored XSS in graph rendering in Checkmk <2.3.0b4.

  • CVE-2025-64996MedNov 18, 2025
    risk 0.29cvss 4.4epss 0.00

    In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates world-readable and writable files, allowing any local user on the system to read the plugin's output and manipulate it, potentially leading to unauthorized access…

  • CVE-2024-38862MedOct 14, 2024
    risk 0.29cvss 4.4epss 0.00

    Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and <=2.0.0p39 (EOL) causes SNMP and IMPI secrets of host and folder properties to be written to audit log files accessible to administrators.

  • CVE-2023-31207MedMay 2, 2023
    risk 0.29cvss 4.4epss 0.00

    Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log.

  • CVE-2026-8833MedJun 8, 2026
    risk 0.28cvss 5.4epss 0.00

    Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validation and inject malicious URLs such as javascript: URIs, resulting in cross-site…

  • CVE-2026-7186MedJun 8, 2026
    risk 0.28cvss 5.4epss 0.00

    Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a dangerous URI scheme such as javascript: that executes scripts in other users'…

  • CVE-2026-3466MedApr 7, 2026
    risk 0.28cvss 5.4epss 0.00

    Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0 allows an attacker with dashboard creation privileges to perform stored cross-site scripting…

  • CVE-2026-33276MedMar 31, 2026
    risk 0.28cvss 5.4epss 0.00

    Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in the Unified Search feature.

  • CVE-2026-20915MedMar 31, 2026
    risk 0.28cvss 5.4epss 0.00

    Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will execute in the browsers of other users viewing the…

  • CVE-2026-24097MedMar 13, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes in agent-receiver/register_existing endpoint, which could lead to…

  • CVE-2025-32916MedOct 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to be included in URL query parameters, which may be logged in various places such as browser history or web…

  • CVE-2024-38857MedJul 2, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper neutralization of input in Checkmk before versions 2.3.0p8, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows attackers to craft malicious links that can facilitate phishing attacks.

  • CVE-2023-22359MedJun 26, 2023
    risk 0.28cvss 4.3epss 0.01

    User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames.

  • CVE-2023-22348MedMay 17, 2023
    risk 0.28cvss 4.3epss 0.01

    Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.

  • CVE-2023-2020MedApr 18, 2023
    risk 0.28cvss 4.3epss 0.00

    Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host.

Page 5 of 6