Zabbix
by Zabbix
Source repositories
CVEs (121)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-27927 | Hig | 0.57 | 8.8 | 0.01 | Mar 3, 2021 | In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the… | ||
| CVE-2016-4338 | Hig | 0.57 | 8.1 | 0.21 | Jan 23, 2017 | The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via… | ||
| CVE-2023-32723 | Hig | 0.55 | 8.5 | 0.01 | Oct 12, 2023 | Request to LDAP is sent before user permissions are checked. | ||
| CVE-2023-29450 | Hig | 0.55 | 8.5 | 0.01 | Jul 13, 2023 | JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data. | ||
| CVE-2017-2824 | Hig | 0.55 | 8.1 | 0.26 | May 24, 2017 | An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection resulting in remote code execution. An attacker can make requests from an active Zabbix Proxy to… | ||
| CVE-2026-23925 | Hig | 0.53 | 8.1 | 0.00 | Mar 6, 2026 | An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit… | ||
| CVE-2024-36460 | Hig | 0.53 | 8.1 | 0.01 | Aug 12, 2024 | The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text. | ||
| CVE-2026-23920 | Hig | 0.50 | — | 0.00 | Mar 24, 2026 | Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands. | ||
| CVE-2024-36467 | Hig | 0.49 | 7.5 | 0.01 | Nov 27, 2024 | An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having… | ||
| CVE-2024-36462 | Hig | 0.49 | 7.5 | 0.01 | Aug 12, 2024 | Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper limitations or controls. This can cause a denial-of-service (DoS) attack or degrade the performance… | ||
| CVE-2023-32721 | Hig | 0.49 | 7.6 | 0.01 | Oct 12, 2023 | A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL. | ||
| CVE-2013-7484 | Hig | 0.49 | 7.5 | 0.01 | Nov 30, 2019 | Zabbix before 5.0 represents passwords in the users table with unsalted MD5. | ||
| CVE-2026-23926 | Hig | 0.47 | — | 0.00 | May 6, 2026 | An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on… | ||
| CVE-2025-27240 | Hig | 0.47 | 7.2 | 0.01 | Sep 12, 2025 | A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field. | ||
| CVE-2025-27234 | Hig | 0.47 | — | 0.00 | Sep 12, 2025 | Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution. | ||
| CVE-2021-46088 | Hig | 0.47 | 7.2 | 0.04 | Jan 27, 2022 | Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user. | ||
| CVE-2026-23919 | Hig | 0.46 | — | 0.00 | Mar 24, 2026 | For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A… | ||
| CVE-2017-2825 | Hig | 0.46 | 7.0 | 0.04 | Apr 20, 2018 | In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to… | ||
| CVE-2026-23923 | Med | 0.45 | — | 0.00 | Mar 24, 2026 | An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time. | ||
| CVE-2023-32727 | Med | 0.44 | 6.8 | 0.01 | Dec 18, 2023 | An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server. |
- risk 0.57cvss 8.8epss 0.01
In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the…
- risk 0.57cvss 8.1epss 0.21
The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via…
- risk 0.55cvss 8.5epss 0.01
Request to LDAP is sent before user permissions are checked.
- risk 0.55cvss 8.5epss 0.01
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.
- risk 0.55cvss 8.1epss 0.26
An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection resulting in remote code execution. An attacker can make requests from an active Zabbix Proxy to…
- risk 0.53cvss 8.1epss 0.00
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit…
- risk 0.53cvss 8.1epss 0.01
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.
- risk 0.50cvss —epss 0.00
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.
- risk 0.49cvss 7.5epss 0.01
An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having…
- risk 0.49cvss 7.5epss 0.01
Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper limitations or controls. This can cause a denial-of-service (DoS) attack or degrade the performance…
- risk 0.49cvss 7.6epss 0.01
A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.
- risk 0.49cvss 7.5epss 0.01
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
- risk 0.47cvss —epss 0.00
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on…
- risk 0.47cvss 7.2epss 0.01
A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
- risk 0.47cvss —epss 0.00
Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.
- risk 0.47cvss 7.2epss 0.04
Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.
- risk 0.46cvss —epss 0.00
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A…
- risk 0.46cvss 7.0epss 0.04
In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to…
- risk 0.45cvss —epss 0.00
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
- risk 0.44cvss 6.8epss 0.01
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
Page 2 of 7