Zabbix
by Zabbix
Source repositories
CVEs (121)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-23134 | Low | 0.43 | 3.7 | 0.85 | KEV | Jan 13, 2022 | After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend. | |
| CVE-2025-49643 | Med | 0.42 | 6.5 | 0.00 | Dec 1, 2025 | An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service. | ||
| CVE-2025-27236 | Med | 0.42 | 6.5 | 0.00 | Oct 3, 2025 | A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to. | ||
| CVE-2024-45700 | Med | 0.42 | 6.5 | 0.00 | Apr 2, 2025 | Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations,… | ||
| CVE-2024-36463 | Med | 0.42 | 6.5 | 0.01 | Nov 26, 2024 | The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects. | ||
| CVE-2022-46768 | Med | 0.42 | 5.9 | 0.48 | Dec 15, 2022 | Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files. | ||
| CVE-2022-43516 | Med | 0.42 | 6.5 | 0.01 | Dec 5, 2022 | A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI) | ||
| CVE-2020-15803 | Med | 0.42 | 6.1 | 0.32 | Jul 17, 2020 | Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget. | ||
| CVE-2023-29457 | Med | 0.41 | 6.3 | 0.01 | Jul 13, 2023 | Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can be sent as request to a website with a vulnerability that enables execution of malicious scripts. | ||
| CVE-2023-29452 | Med | 0.41 | 5.5 | 0.64 | Jul 13, 2023 | Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Other” Tile provider. | ||
| CVE-2022-23133 | Med | 0.41 | 6.3 | 0.01 | Jan 13, 2022 | An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire… | ||
| CVE-2026-23924 | Med | 0.40 | — | 0.00 | Mar 24, 2026 | Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API. | ||
| CVE-2024-22121 | Med | 0.40 | 6.1 | 0.00 | Aug 12, 2024 | A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the application. | ||
| CVE-2016-10742 | Med | 0.40 | 6.1 | 0.03 | Feb 17, 2019 | Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter. | ||
| CVE-2023-29458 | Med | 0.38 | 5.9 | 0.01 | Jul 13, 2023 | Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an 3rd-party solution that we use. | ||
| CVE-2023-29449 | Med | 0.38 | 5.9 | 0.01 | Jul 13, 2023 | JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should… | ||
| CVE-2023-29456 | Med | 0.37 | 5.7 | 0.01 | Jul 13, 2023 | URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards. | ||
| CVE-2024-22119 | Med | 0.36 | 5.5 | 0.01 | Feb 9, 2024 | The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section. | ||
| CVE-2024-45699 | Med | 0.35 | 5.4 | 0.00 | Apr 2, 2025 | The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be… | ||
| CVE-2023-29455 | Med | 0.35 | 5.4 | 0.01 | Jul 13, 2023 | Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated through a link, which sends a request to a website with a vulnerability that enables execution of… |
- risk 0.43cvss 3.7epss 0.85
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.
- risk 0.42cvss 6.5epss 0.00
An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.
- risk 0.42cvss 6.5epss 0.00
A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
- risk 0.42cvss 6.5epss 0.00
Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations,…
- risk 0.42cvss 6.5epss 0.01
The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects.
- risk 0.42cvss 5.9epss 0.48
Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.
- risk 0.42cvss 6.5epss 0.01
A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI)
- risk 0.42cvss 6.1epss 0.32
Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.
- risk 0.41cvss 6.3epss 0.01
Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can be sent as request to a website with a vulnerability that enables execution of malicious scripts.
- risk 0.41cvss 5.5epss 0.64
Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Other” Tile provider.
- risk 0.41cvss 6.3epss 0.01
An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire…
- risk 0.40cvss —epss 0.00
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.
- risk 0.40cvss 6.1epss 0.00
A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the application.
- risk 0.40cvss 6.1epss 0.03
Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.
- risk 0.38cvss 5.9epss 0.01
Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an 3rd-party solution that we use.
- risk 0.38cvss 5.9epss 0.01
JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should…
- risk 0.37cvss 5.7epss 0.01
URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards.
- risk 0.36cvss 5.5epss 0.01
The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.
- risk 0.35cvss 5.4epss 0.00
The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be…
- risk 0.35cvss 5.4epss 0.01
Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated through a link, which sends a request to a website with a vulnerability that enables execution of…
Page 3 of 7