VYPR

Vendor CVEs

Centreon

All CVEs

139 total · sorted by risk
  • CVE-2025-4646HigMay 13, 2025
    risk 0.47cvss 7.2epss 0.00

    Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.

  • CVE-2025-3872HigApr 24, 2025
    risk 0.47cvss 7.2epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-web (User configuration form modules) allows SQL Injection. A user with high privileges is able to become administrator by intercepting the contact form…

  • CVE-2024-45757HigDec 3, 2024
    risk 0.47cvss 7.2epss 0.00

    An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10. SQL injection can occur in the user-settings form. Exploitation is only accessible to authenticated users with high-privileged access.

  • CVE-2024-45756HigNov 25, 2024
    risk 0.47cvss 7.2epss 0.00

    An issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0, 24.04.x before 24.04.2, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to create a ticket. Exploitation is only accessible to…

  • CVE-2024-39842HigSep 23, 2024
    risk 0.47cvss 7.2epss 0.02

    A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via user massive changes inputs.

  • CVE-2022-34871HigAug 3, 2022
    risk 0.47cvss 7.2epss 0.03

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of poller resources. The issue results from the lack of proper…

  • CVE-2024-23115HigApr 1, 2024
    risk 0.45cvss 7.2epss 0.67

    Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2019-16405HigNov 21, 2019
    risk 0.45cvss 7.2epss 0.27

    Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location settings. CVE-2019-16405 and CVE-2019-17501 are similar to one another and may be the…

  • CVE-2025-12513MedJan 5, 2026
    risk 0.44cvss 6.8epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hosts configuration form modules) allows Stored XSS to users with high privileges. This issue affects Infra Monitoring: from 25.10.0 before…

  • CVE-2025-12511MedJan 5, 2026
    risk 0.44cvss 6.8epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (DSM extenstio configuration modules) allows Stored XSS to user with elevated privileges. This issue affects Infra Monitoring: from 25.10.0…

  • CVE-2025-13056MedJan 5, 2026
    risk 0.44cvss 6.8epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Administration ACL menu configuration modules) allows Stored XSS to users with high privileges. This issue affects Infra Monitoring: from…

  • CVE-2025-8460MedDec 22, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Notification rules, Open tickets module) allows Stored XSS by users with elevated privileges.This issue affects Infra Monitoring: from…

  • CVE-2025-54890MedDec 22, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hostgroup configuration page) allows Stored XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before…

  • CVE-2025-8430MedOct 14, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Commands Connectors configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from…

  • CVE-2025-8429MedOct 14, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (ACL Action access configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from…

  • CVE-2025-54893MedOct 14, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hosts templates configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from…

  • CVE-2025-8428MedOct 14, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (HTTP Loader widget modules) allows Stored XSS.This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18,…

  • CVE-2025-54892MedOct 14, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps group configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from…

  • CVE-2025-54891MedOct 14, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (ACL Resource access configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from…

  • CVE-2025-54889MedOct 14, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps manufacturer configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from…

  • CVE-2024-39843MedSep 23, 2024
    risk 0.44cvss 6.7epss 0.02

    A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via create user form inputs.

  • CVE-2024-23118HigApr 1, 2024
    risk 0.44cvss 7.2epss 0.53

    Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists…

  • CVE-2024-23117HigApr 1, 2024
    risk 0.44cvss 7.2epss 0.53

    Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw…

  • CVE-2024-23116HigApr 1, 2024
    risk 0.44cvss 7.2epss 0.53

    Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within…

  • CVE-2019-16406HigNov 21, 2019
    risk 0.44cvss 7.8epss 0.00

    Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual machine) files, allowing attackers to gain privileges via a Trojan horse Centreon-autodisco executable file that is launched by cron.

  • CVE-2022-34872MedAug 3, 2022
    risk 0.42cvss 6.5epss 0.02

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of Virtual Metrics. The issue results from the lack of…

  • CVE-2021-26804MedMay 4, 2021
    risk 0.42cvss 6.5epss 0.01

    Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.

  • CVE-2019-19486MedMar 20, 2020
    risk 0.42cvss 6.5epss 0.02

    Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a plugin test.

  • CVE-2019-17646HigMar 5, 2020
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreon_metric&action=listByService.

  • CVE-2025-10023MedOct 27, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Services Meta-services modules) allows Stored XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before…

  • CVE-2025-3767HigApr 22, 2025
    risk 0.40cvss 7.2epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Boolean KPi Listing modules) allows SQL Injection. This page is only accessible to authenticated users with high privileges. This issue affects Centreon BAM:…

  • CVE-2024-45755HigNov 25, 2024
    risk 0.40cvss 7.2epss 0.00

    An issue was discovered in Centreon centreon-dsm-server 24.10.x before 24.10.0, 24.04.x before 24.04.3, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to configure Centreon DSM slots. Exploitation is only…

  • CVE-2024-45754HigOct 11, 2024
    risk 0.40cvss 7.2epss 0.01

    An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before 23.10.8, 23.04.x before 23.04.11, and 22.10.x before 22.10.11. SQL injection can occur in the listing of configured reporting jobs. Exploitation is only…

  • CVE-2020-13628MedMay 27, 2020
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to host-monitoring/src/toolbar.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring…

  • CVE-2020-13627MedMay 27, 2020
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring…

  • CVE-2020-10946MedMay 27, 2020
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget;…

  • CVE-2019-19484MedMar 20, 2020
    risk 0.40cvss 6.1epss 0.01

    Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior.

  • CVE-2022-39988MedOct 6, 2022
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability in Centreon 22.04.0 allows attackers to execute arbitrary web script or HTML via a crafted payload injected into the Service>Templates service_alias parameter.

  • CVE-2022-36194MedAug 29, 2022
    risk 0.35cvss 5.4epss 0.01

    Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted payload into the name parameter.

  • CVE-2021-28054MedJul 16, 2021
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A Stored Cross-Site Scripting (XSS) issue in "Configuration > Hosts" allows remote authenticated users to inject arbitrary web script or HTML via the Alias parameter.

  • CVE-2021-27676MedMay 26, 2021
    risk 0.35cvss 5.4epss 0.01

    Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Description) and dep_name (Dependency Name) parameters are vulnerable to stored XSS. A user has to log in and go to the Configuration > Notifications > Hosts page.

  • CVE-2021-28055MedApr 15, 2021
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user.

  • CVE-2025-12519MedJan 5, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not Properly Constrained by ACLs, resulting in Information Disclosure like downtime or acknowledgement configurations. This issue…

  • CVE-2022-3827MedNov 2, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the file formContactGroup.php of the component Contact Groups Form. The manipulation of the argument cg_id leads to sql injection. The attack can be initiated…

  • CVE-2024-47863MedNov 22, 2024
    risk 0.33cvss 6.2epss 0.01

    An issue was discovered in Centreon Web 24.10.x before 24.10.0, 24.04.x before 24.04.8, 23.10.x before 23.10.18, 23.04.x before 23.04.23, and 22.10.x before 22.10.26. A stored XSS was found in the user configuration contact name field. This form is only accessible to…

  • CVE-2019-16195MedNov 26, 2019
    risk 0.33cvss 6.1epss 0.01

    Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.

  • CVE-2025-4649MedMay 13, 2025
    risk 0.32cvss 4.9epss 0.00

    Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. This issue affects…

  • CVE-2022-40044MedSep 26, 2022
    risk 0.28cvss 5.4epss 0.01

    Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted…

  • CVE-2019-17105MedOct 8, 2019
    risk 0.28cvss 5.3epss 0.02

    The token generator in index.php in Centreon Web before 2.8.27 is predictable.

  • CVE-2015-7672MedSep 7, 2017
    risk 0.28cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27).