📦 Centreon Web

by Centreon

🔍 What is Centreon Web?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-55573

CRITICAL CVSS 9.1 Jan 23, 2025

A critical SQL injection vulnerability in Centreon centreon-web allows authenticated users with high privileges to inject malicious SQL queries when creating virtual metrics. This affects Centreon mon...

CVE-2024-53923

CRITICAL CVSS 9.1 Jan 23, 2025

This vulnerability allows authenticated users with high privileges in Centreon Web to perform SQL injection via the media upload form. Attackers could execute arbitrary SQL commands, potentially compr...

CVE-2024-32501

CRITICAL CVSS 9.8 Aug 23, 2024

A SQL injection vulnerability in Centreon Web's updateServiceHost function allows attackers to execute arbitrary SQL commands. This affects all Centreon Web installations running vulnerable versions, ...

CVE-2024-33853

CRITICAL CVSS 9.1 Aug 23, 2024

A SQL injection vulnerability in the Timeperiod component of Centreon Web allows attackers to execute arbitrary SQL commands. This affects Centreon Web versions 24.04.x before 24.04.3, 23.10.x before ...

CVE-2023-51633

CRITICAL CVSS 9.6 May 3, 2024

This is a cross-site scripting (XSS) vulnerability in Centreon's SNMP sysName OID processing that allows remote code execution. Attackers can inject malicious scripts that execute with service account...

CVE-2025-5965

HIGH CVSS 7.2 Jan 5, 2026

This vulnerability allows authenticated users with high privileges to inject arbitrary operating system commands through backup configuration parameters in Centreon Infra Monitoring. Successful exploi...

CVE-2025-8459

HIGH CVSS 7.7 Oct 14, 2025

This stored XSS vulnerability in Centreon Infra Monitoring allows attackers to inject malicious scripts into web pages through the recurrent downtime scheduler modules. When users view affected pages,...

CVE-2025-5946

HIGH CVSS 7.2 Oct 14, 2025

This OS command injection vulnerability in Centreon Infra Monitoring allows authenticated high-privilege users to inject arbitrary commands into poller reload operations. Attackers could execute syste...

CVE-2025-6791

HIGH CVSS 8.8 Aug 22, 2025

This SQL injection vulnerability in Centreon web's monitoring event logs module allows attackers to manipulate HTTP requests to inject malicious SQL payloads into the database. It affects all Centreon...

CVE-2025-4650

HIGH CVSS 7.2 Aug 22, 2025

A high-privilege user can perform SQL injection attacks through the Meta Service indicator page in Centreon web interface. This vulnerability affects Centreon web versions 24.10.0-24.10.8, 24.04.0-24....

CVE-2025-4646

HIGH CVSS 7.2 May 13, 2025

An incorrect authorization vulnerability in Centreon web's API token creation form allows authenticated users to create API tokens with higher privileges than intended. This affects Centreon web insta...

CVE-2025-4648

HIGH CVSS 8.4 May 13, 2025

This vulnerability allows reflected cross-site scripting (XSS) in Centreon web interface via malicious SVG file uploads. An authenticated user with elevated privileges can inject JavaScript by manipul...

CVE-2025-3872

HIGH CVSS 7.2 Apr 24, 2025

This SQL injection vulnerability in Centreon's web interface allows high-privileged users to become administrators by manipulating contact form requests. It affects Centreon monitoring software across...

CVE-2024-39841

HIGH CVSS 8.8 Aug 23, 2024

A SQL injection vulnerability in Centreon Web's service configuration functionality allows attackers to execute arbitrary SQL commands. This affects Centreon Web versions 24.04.x before 24.04.3, 23.10...

CVE-2024-5725

HIGH CVSS 8.8 Aug 21, 2024

This SQL injection vulnerability in Centreon's initCurveList function allows authenticated remote attackers to execute arbitrary SQL commands, potentially leading to remote code execution as the apach...

CVE-2024-23118

HIGH CVSS 7.2 Apr 1, 2024

This SQL injection vulnerability in Centreon's updateContactHostCommands function allows authenticated attackers to execute arbitrary SQL commands, potentially leading to remote code execution. Affect...

CVE-2024-23116

HIGH CVSS 7.2 Apr 1, 2024

This SQL injection vulnerability in Centreon's updateLCARelation function allows authenticated remote attackers to execute arbitrary SQL commands, potentially leading to remote code execution. Attacke...

CVE-2024-0637

HIGH CVSS 8.8 Apr 1, 2024

This SQL injection vulnerability in Centreon's updateDirectory function allows authenticated remote attackers to execute arbitrary SQL commands, potentially leading to remote code execution. Affected ...

CVE-2025-54890

MEDIUM CVSS 6.8 Dec 22, 2025

This stored cross-site scripting (XSS) vulnerability in Centreon Infra Monitoring allows authenticated users with elevated privileges to inject malicious scripts into the Hostgroup configuration page....

CVE-2025-8430

MEDIUM CVSS 6.8 Oct 14, 2025

This stored XSS vulnerability in Centreon Infra Monitoring allows authenticated users with elevated privileges to inject malicious scripts into the Commands Connectors configuration modules. When othe...

CVE-2025-8429

MEDIUM CVSS 6.8 Oct 14, 2025

This stored XSS vulnerability in Centreon Infra Monitoring allows authenticated users with elevated privileges to inject malicious scripts into ACL Action access configuration modules. When other user...

CVE-2025-54893

MEDIUM CVSS 6.8 Oct 14, 2025

This stored XSS vulnerability in Centreon Infra Monitoring allows authenticated users with elevated privileges to inject malicious scripts into host template configuration pages. When other users view...

CVE-2025-54892

MEDIUM CVSS 6.8 Oct 14, 2025

This stored XSS vulnerability in Centreon Infra Monitoring allows authenticated users with elevated privileges to inject malicious scripts into SNMP traps group configuration modules. When other users...

CVE-2025-54891

MEDIUM CVSS 6.8 Oct 14, 2025

This stored XSS vulnerability in Centreon Infra Monitoring allows authenticated users with elevated privileges to inject malicious scripts into ACL Resource access configuration modules. When other us...

CVE-2025-54889

MEDIUM CVSS 6.8 Oct 14, 2025

This stored XSS vulnerability in Centreon Infra Monitoring allows attackers with elevated privileges to inject malicious scripts into SNMP trap manufacturer configuration pages. When other users view ...

CVE-2025-4649

MEDIUM CVSS 4.9 May 13, 2025

A privilege escalation vulnerability in Centreon web allows users with lower privileges to view event logs that should require high privileges. This occurs because Access Control Lists (ACLs) are not ...