VYPR

Vendor CVEs

Centreon

All CVEs

139 total · sorted by risk
  • CVE-2025-15029CriJan 5, 2026
    risk 0.65cvss 9.8epss 0.11

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0…

  • CVE-2024-32501CriAug 23, 2024
    risk 0.65cvss 9.8epss 0.19

    A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2026-2749CriFeb 27, 2026
    risk 0.64cvss 9.9epss 0.00

    Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7.

  • CVE-2025-15026CriJan 5, 2026
    risk 0.64cvss 9.8epss 0.00

    Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before…

  • CVE-2022-41142HigJan 26, 2023
    risk 0.64cvss 8.8epss 0.86

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to configure poller resources. The issue results from the…

  • CVE-2018-21025CriOct 8, 2019
    risk 0.64cvss 9.8epss 0.03

    In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced configuration files.

  • CVE-2022-42429HigMar 29, 2023
    risk 0.63cvss 8.8epss 0.78

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results…

  • CVE-2022-42427HigMar 29, 2023
    risk 0.63cvss 8.8epss 0.76

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the contact groups configuration page. The issue results from the lack of proper…

  • CVE-2022-42425HigMar 29, 2023
    risk 0.63cvss 8.8epss 0.76

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results…

  • CVE-2022-42424HigMar 29, 2023
    risk 0.63cvss 8.8epss 0.76

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results…

  • CVE-2023-51633CriMay 3, 2024
    risk 0.62cvss 9.6epss 0.01

    Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. User interaction is required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2024-5723HigAug 21, 2024
    risk 0.60cvss 8.8epss 0.41

    Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within…

  • CVE-2021-37557HigAug 3, 2021
    risk 0.60cvss 8.8epss 0.29

    A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/views/graphs/generateGraphs/generateImage.php index parameter.

  • CVE-2026-2750CriFeb 27, 2026
    risk 0.59cvss 9.1epss 0.00

    Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10; 24.10;24.04.

  • CVE-2024-55573CriJan 23, 2025
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to inject SQL into the form used to create virtual metrics.

  • CVE-2024-53923CriJan 23, 2025
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to achieve SQL injection in the form to upload media.

  • CVE-2024-33854CriAug 23, 2024
    risk 0.59cvss 9.1epss 0.00

    A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2024-33853CriAug 23, 2024
    risk 0.59cvss 9.1epss 0.00

    A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2024-33852CriAug 23, 2024
    risk 0.59cvss 9.1epss 0.00

    A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2019-19487HigMar 20, 2020
    risk 0.58cvss 8.8epss 0.05

    Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.

  • CVE-2020-9463HigFeb 28, 2020
    risk 0.58cvss 8.8epss 0.04

    Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an api/internal.php?object=centreon_configuration_remote request.

  • CVE-2025-6791HigAug 22, 2025
    risk 0.57cvss 8.8epss 0.00

    In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon web (Monitoring event logs modules)…

  • CVE-2022-42428HigMar 29, 2023
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results…

  • CVE-2022-42426HigMar 29, 2023
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results…

  • CVE-2021-28053HigJul 16, 2021
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A SQL injection vulnerability in "Configuration > Users > Contacts / Users" allows remote authenticated users to execute arbitrary SQL commands via the Additional Information parameters.

  • CVE-2020-22425HigFeb 15, 2021
    risk 0.57cvss 8.8epss 0.02

    Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an authorized user is able to inject additional SQL queries to perform remote command execution.

  • CVE-2019-17642HigMar 5, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharacters in a POST to centreon-autodiscovery-server/views/scan/ajax/call.php in the Autodiscovery plugin.

  • CVE-2019-17501HigOct 14, 2019
    risk 0.57cvss 8.8epss 0.02

    Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command Line field of main.php?p=60807&type=4 (aka the Configuration > Commands > Discovery screen). CVE-2019-17501 and CVE-2019-16405 are similar to one another and may be the same.

  • CVE-2019-16194CriSep 25, 2019
    risk 0.57cvss 9.8epss 0.02

    SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOneService.php.

  • CVE-2024-0637HigApr 1, 2024
    risk 0.56cvss 8.8epss 0.72

    Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2026-14453CriJul 13, 2026
    risk 0.55cvss 9.6epss 0.01

    This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without sanitization and rendered via Smarty with no security policy enabled, allowing any…

  • CVE-2025-8432HigOct 27, 2025
    risk 0.55cvss 8.4epss 0.00

    Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 before 24.04.9, from…

  • CVE-2025-4648HigMay 13, 2025
    risk 0.55cvss 8.4epss 0.00

    The content of a SVG file, received as input in Centreon web, was not properly checked. Allows Reflected XSS. A user with elevated privileges can inject JS script by altering the content of a SVG media, during the submit request. This issue affects web: from 24.10.0 before…

  • CVE-2025-4647HigMay 13, 2025
    risk 0.55cvss 8.4epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon web allows Reflected XSS. A user with elevated privileges can bypass sanitization measures by replacing the content of an existing SVG. This issue affects web:…

  • CVE-2026-2751HigFeb 27, 2026
    risk 0.54cvss 8.3epss 0.00

    Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (Service Dependencies modules) allows Blind SQL Injection.This issue affects Centreon Web on Central Server before 25.10.8,…

  • CVE-2024-5725HigAug 21, 2024
    risk 0.54cvss 8.8epss 0.47

    Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2019-19699HigApr 6, 2020
    risk 0.52cvss 7.2epss 0.28

    There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at…

  • CVE-2025-5946HigOct 14, 2025
    risk 0.51cvss 7.2epss 0.14

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload setup in the configuration modules) allows OS Command Injection. On the poller parameters page, a user with high privilege is able…

  • CVE-2019-20327HigJan 16, 2020
    risk 0.51cvss 7.8epss 0.00

    Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Software through 19.10 allow local attackers to gain privileges. (cwrapper_perl is a setuid executable allowing execution of Perl scripts with root privileges.)

  • CVE-2025-8459HigOct 14, 2025
    risk 0.50cvss 7.7epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Monitoring recurrent downtime scheduler modules) allows Stored XSS.This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from…

  • CVE-2024-39841HigAug 23, 2024
    risk 0.50cvss 8.8epss 0.01

    A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2024-23119HigApr 1, 2024
    risk 0.50cvss 8.8epss 0.01

    Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within…

  • CVE-2022-40043HigSep 26, 2022
    risk 0.50cvss 8.8epss 0.01

    Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations.

  • CVE-2019-17107HigOct 8, 2019
    risk 0.50cvss 8.8epss 0.04

    minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the command_hostaddress parameter. NOTE: some sources have listed CVE-2019-17017 for this, but that is incorrect.

  • CVE-2025-5965HigJan 5, 2026
    risk 0.49cvss 7.2epss 0.26

    In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Backup configuration in the…

  • CVE-2019-17644HigMar 4, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Centreon before 2.8-30, 18.10-8, 19.04-5, and 19.10-2.. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/host/refreshMacroAjax.php.

  • CVE-2019-17643HigMar 4, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Centreon before 2.8-30,18.10-8, 19.04-5, and 19.10-2. It provides sensitive information via an unauthenticated direct request for include/monitoring/recurrentDowntime/GetXMLHost4Services.php.

  • CVE-2019-17104HigOct 8, 2019
    risk 0.49cvss 7.5epss 0.02

    In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft because the HTTPOnly flag is not set.

  • CVE-2025-12514HigDec 22, 2025
    risk 0.47cvss 7.2epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring - Open-tickets (Notification rules configuration parameters, Open tickets modules) allows SQL Injection to user with elevated privileges.This issue…

  • CVE-2025-4650HigAug 22, 2025
    risk 0.47cvss 7.2epss 0.00

    User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutralization of Special Elements used in an SQL Command.This issue affects web: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before…

Page 1 of 3