Home/Product/centreon
Product

centreon

127 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-2749
< 24.04.7
Vulnerability in Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centr
9.9CRITICAL
CVE-2026-2751
>= 24.04.0 and < 24.04.24.
Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Web on Central
8.3HIGH
CVE-2025-15029
>= 24.04.0 and < 24.04.3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (A
9.8CRITICAL
CVE-2025-15026
>= 24.04.0 and < 24.04.3
Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows
9.8CRITICAL
CVE-2025-12513
>= 24.04.0 and < 24.04.19
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-13056
>= 24.04.0 and < 24.04.19
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-12519
>= 24.04.0 and < 24.04.19
Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing
5.3MEDIUM
CVE-2025-5965
>= 24.04.0 and < 24.04.19
In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Improper Neut
7.2HIGH
CVE-2025-8460
>= 23.10.0 and < 23.10.4
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-54890
>= 23.10.0 and < 23.10.29
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-12514
>= 23.10.0 and < 23.10.4
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring -
7.2HIGH
CVE-2025-10023
>= 23.10.0 and < 23.10.26
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.2MEDIUM
CVE-2025-8459
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
7.7HIGH
CVE-2025-8430
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-8429
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-54893
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-8428
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-5946
>= 23.10.0 and < 23.10.28
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitor
7.2HIGH
CVE-2025-54892
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-54891
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-54889
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-6791
>= 23.10.0 and < 23.10.26
In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Im
8.8HIGH
CVE-2025-4650
>= 23.10.0 and < 23.10.26
User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutralization
7.2HIGH
CVE-2025-4649
>= 23.04.24 and < 23.04.26
Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly ta
4.9MEDIUM
CVE-2025-4648
>= 22.10.0 and < 22.10.29
The content of a SVG file, received as input in Centreon web, was not properly checked. Allows Reflected XSS. A user with elevat
8.4HIGH
CVE-2025-4647
>= 22.10.0 and < 22.10.29
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon web allows R
8.4HIGH
CVE-2025-4646
>= 24.04.0 and < 24.04.10
Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue aff
7.2HIGH
CVE-2025-3872
>= 22.10.0 and < 22.10.28
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-web (User
7.2HIGH
CVE-2024-55573
>= 23.04.0 and < 23.04.24
An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x
9.1CRITICAL
CVE-2024-53923
>= 23.04.0 and < 23.04.24
An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23
9.1CRITICAL
CVE-2024-39843
all versions
A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via cr
6.7MEDIUM
CVE-2024-39842
all versions
A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via us
7.2HIGH
CVE-2024-39841
>= 22.10.0 and < 22.10.23
A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x be
8.8HIGH
CVE-2024-33854
>= 22.10.0 and < 22.10.23
A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.
9.1CRITICAL
CVE-2024-33853
>= 22.10.0 and < 22.10.23
A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13,
9.1CRITICAL
CVE-2024-33852
>= 22.10.0 and < 22.10.23
A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23
9.1CRITICAL
CVE-2024-32501
>= 22.10.0 and < 22.10.23
A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before
9.8CRITICAL
CVE-2024-5725
< 22.10.23
Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute ar
8.8HIGH
CVE-2024-5723
< 22.04.24
Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut
8.8HIGH
CVE-2023-51633
< 22.10.15
Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a
9.6CRITICAL
CVE-2024-23119
< 22.04.19
Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec
8.8HIGH
CVE-2024-23118
< 22.04.19
Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers t
7.2HIGH
CVE-2024-23117
< 22.04.19
Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attacker
7.2HIGH
CVE-2024-23116
< 22.04.19
Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut
7.2HIGH
CVE-2024-23115
< 22.04.19
Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb
7.2HIGH
CVE-2024-0637
< 22.04.19
Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute
8.8HIGH
CVE-2022-42429
< 21.04.19
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is require
8.8HIGH
CVE-2022-42428
< 21.04.19
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is require
8.8HIGH
CVE-2022-42427
< 21.10.11
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is require
8.8HIGH
CVE-2022-42426
< 21.04.19
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is require
8.8HIGH
CVE-2022-42425
< 21.04.19
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is require
8.8HIGH
CVE-2022-42424
< 21.04.19
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is require
8.8HIGH
CVE-2022-41142
all versions
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is require
8.8HIGH
CVE-2022-3827
< 22.10.0
A vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the file formC
6.3MEDIUM
CVE-2022-39988
all versions
A cross-site scripting (XSS) vulnerability in Centreon 22.04.0 allows attackers to execute arbitrary web script or HTML via a craf
5.4MEDIUM
CVE-2022-40044
all versions
Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) paramet
5.4MEDIUM
CVE-2022-40043
all versions
Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter at Configu
8.8HIGH
CVE-2022-36194
all versions
Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted
5.4MEDIUM
CVE-2022-34872
all versions
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Centreon. Authentication
6.5MEDIUM
CVE-2022-34871
all versions
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is require
7.2HIGH
CVE-2020-22345
all versions
/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metac
8.8HIGH
CVE-2021-37558
< 20.04.14
A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticate
9.8CRITICAL
CVE-2021-37557
< 20.04.14
A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (b
8.8HIGH
CVE-2021-37556
< 20.04.14
A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (b
8.8HIGH
CVE-2021-28053
all versions
An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A SQL injection vulnerability in "Configuration > Users > Co
8.8HIGH
CVE-2021-28054
all versions
An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A Stored Cross-Site Scripting (XSS) issue in "Configuration
5.4MEDIUM
CVE-2021-27676
all versions
Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Description) a
5.4MEDIUM
CVE-2021-26804
all versions
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by chang
6.5MEDIUM
CVE-2021-28055
all versions
An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might a
6.5MEDIUM
CVE-2020-22425
all versions
Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an authorized user is able to inject additional SQL queri
8.8HIGH
CVE-2020-13628
< 1.6.4
Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter
6.1MEDIUM
CVE-2020-13627
< 1.6.4
Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter
6.1MEDIUM
CVE-2020-10946
< 1.6.4
Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to
6.1MEDIUM
CVE-2020-10945
<= 2.8.2
Centreon before 19.10.7 exposes Session IDs in server responses.
4.3MEDIUM
CVE-2020-13252
>= 19.04.0 and < 19.04.15
Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_s
8.8HIGH
CVE-2019-19699
<= 19.10
There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfigura
7.2HIGH
CVE-2019-19487
<= 19.04.4
Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plug
8.8HIGH
CVE-2019-19486
<= 19.04.4
Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a plugin test.
6.5MEDIUM
CVE-2019-19484
<= 19.04.4
Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute
6.1MEDIUM
CVE-2019-17647
< 2.8.30
An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/
9.8CRITICAL
CVE-2019-17646
>= 18.0.0 and < 18.10.8
An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated
7.5HIGH
CVE-2019-17645
< 2.8.31
An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3. It provides sensitive information via an unauthe
7.5HIGH
CVE-2019-17642
>= 18.0.0 and < 18.10.8
An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution v
8.8HIGH
CVE-2019-17644
< 2.8.30
An issue was discovered in Centreon before 2.8-30, 18.10-8, 19.04-5, and 19.10-2.. It provides sensitive information via an unauth
7.5HIGH
CVE-2019-17643
< 2.8.30
An issue was discovered in Centreon before 2.8-30,18.10-8, 19.04-5, and 19.10-2. It provides sensitive information via an unauthen
7.5HIGH
CVE-2020-9463
all versions
Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field
8.8HIGH
CVE-2019-15299
<= 19.04.3
An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autolog
8.8HIGH
CVE-2019-20327
<= 19.10
Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Software through 19.10 allow local attackers to gain p
7.8HIGH
CVE-2019-15300
>= 2.8.1 and < 2.8.30
A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/
8.8HIGH
CVE-2019-15298
>= 2.8.1 and < 2.8.30
A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configurati
8.8HIGH
CVE-2019-16195
>= 2.8.0 and < 2.8.30
Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.
6.1MEDIUM
CVE-2019-16406
all versions
Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual machine) fil
7.8HIGH
CVE-2019-16405
< 2.8.30
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution
7.2HIGH
CVE-2019-17501
all versions
Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command Line field of main.php?p=60807&type=4 (aka the Co
8.8HIGH
CVE-2019-17105
>= 2.8 and < 2.8.27
The token generator in index.php in Centreon Web before 2.8.27 is predictable.
5.3MEDIUM
CVE-2018-21024
< 2.8.27
licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.
9.8CRITICAL
CVE-2019-17108
>= 2.8 and < 2.8.28
Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a
6.1MEDIUM
CVE-2019-17107
>= 2.8 and < 2.8.27
minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the command_hostaddr
8.8HIGH
CVE-2019-17106
<= 2.8.29
In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to e
6.5MEDIUM
CVE-2018-21023
>= 2.8 and < 2.8.28
getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter.
8.8HIGH
CVE-2018-21022
< 2.8.28
makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parameter.
8.8HIGH
CVE-2018-21021
< 2.8.27
img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter.
8.8HIGH
CVE-2018-21020
< 2.8.27
In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows attackers to
7.5HIGH
CVE-2019-16194
<= 19.04.0
SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Servic
9.8CRITICAL
CVE-2019-13024
all versions
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system
8.8HIGH
CVE-2018-19312
>= 3.4.0 and <= 3.4.9
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php
8.8HIGH
CVE-2018-19311
>= 3.4.0 and <= 3.4.9
Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "M
5.4MEDIUM
CVE-2018-19281
all versions
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.
9.8CRITICAL
CVE-2018-19280
>= 3.4.0 and <= 3.4.9
Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.
6.1MEDIUM
CVE-2018-19271
all versions
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL Injection via the main.php searchH parameter.
8.8HIGH
CVE-2018-11589
all versions
Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in
9.8CRITICAL
CVE-2018-11588
all versions
Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or comma
5.4MEDIUM
CVE-2018-11587
all versions
There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in cen
9.8CRITICAL
CVE-2015-7672
all versions
Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27).
5.4MEDIUM
CVE-2015-1561
<= 2.5.4
The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4
CVE-2015-1560
<= 2.5.4
SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon)
CVE-2014-3829
all versions
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attacker
CVE-2014-3828
all versions
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow re
CVE-2012-5967
all versions
SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote authentic
CVE-2011-4432
<= 2.3.1
www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculati
CVE-2011-4431
<= 2.3.1
Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbit
CVE-2010-1301
all versions
SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via the host_i
CVE-2009-4368
<= 2.1.3
Multiple unspecified vulnerabilities in Centreon before 2.1.4 have unknown impact and attack vectors in the (1) ping tool, (2) tra
CVE-2008-1179
<= 1.4.2.3
Multiple cross-site scripting (XSS) vulnerabilities in include/common/javascript/color_picker.php in Centreon 1.4.2.3 and earlier
CVE-2008-1178
<= 1.4.2.3
Directory traversal vulnerability in include/doc/index.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitra
CVE-2008-1119
<= 1.4.2.3
Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arb
CVE-2007-6485
all versions
Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary P
threatengine.sh