Home/Product/centreon web
Product

centreon web

57 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-2750
< 24.04.24
Improper Input Validation vulnerability in Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets module
9.1CRITICAL
CVE-2026-2751
>= 24.04.0 and < 24.04.24.
Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Web on Central
8.3HIGH
CVE-2025-12513
>= 24.04.0 and < 24.04.19
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-13056
>= 24.04.0 and < 24.04.19
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-12519
>= 24.04.0 and < 24.04.19
Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing
5.3MEDIUM
CVE-2025-5965
>= 24.04.0 and < 24.04.19
In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Improper Neut
7.2HIGH
CVE-2025-54890
>= 23.10.0 and < 23.10.29
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-10023
>= 23.10.0 and < 23.10.26
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.2MEDIUM
CVE-2025-8459
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
7.7HIGH
CVE-2025-8430
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-8429
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-54893
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-8428
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-5946
>= 23.10.0 and < 23.10.28
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitor
7.2HIGH
CVE-2025-54892
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-54891
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-54889
>= 23.10.0 and < 23.10.28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monito
6.8MEDIUM
CVE-2025-6791
>= 23.10.0 and < 23.10.26
In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Im
8.8HIGH
CVE-2025-4650
>= 23.10.0 and < 23.10.26
User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutralization
7.2HIGH
CVE-2025-4649
>= 23.04.24 and < 23.04.26
Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly ta
4.9MEDIUM
CVE-2025-4648
>= 22.10.0 and < 22.10.29
The content of a SVG file, received as input in Centreon web, was not properly checked. Allows Reflected XSS. A user with elevat
8.4HIGH
CVE-2025-4647
>= 22.10.0 and < 22.10.29
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon web allows R
8.4HIGH
CVE-2025-4646
>= 24.04.0 and < 24.04.10
Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue aff
7.2HIGH
CVE-2025-3872
>= 22.10.0 and < 22.10.28
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-web (User
7.2HIGH
CVE-2024-55573
>= 23.04.0 and < 23.04.24
An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x
9.1CRITICAL
CVE-2024-53923
>= 23.04.0 and < 23.04.24
An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23
9.1CRITICAL
CVE-2024-39841
>= 22.10.0 and < 22.10.23
A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x be
8.8HIGH
CVE-2024-33854
>= 22.10.0 and < 22.10.23
A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.
9.1CRITICAL
CVE-2024-33853
>= 22.10.0 and < 22.10.23
A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13,
9.1CRITICAL
CVE-2024-33852
>= 22.10.0 and < 22.10.23
A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23
9.1CRITICAL
CVE-2024-32501
>= 22.10.0 and < 22.10.23
A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before
9.8CRITICAL
CVE-2024-5725
< 22.10.23
Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute ar
8.8HIGH
CVE-2024-5723
< 22.04.24
Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut
8.8HIGH
CVE-2023-51633
< 22.10.15
Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a
9.6CRITICAL
CVE-2024-23119
< 22.04.19
Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec
8.8HIGH
CVE-2024-23118
< 22.04.19
Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers t
7.2HIGH
CVE-2024-23117
< 22.04.19
Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attacker
7.2HIGH
CVE-2024-23116
< 22.04.19
Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut
7.2HIGH
CVE-2024-23115
< 22.04.19
Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb
7.2HIGH
CVE-2024-0637
< 22.04.19
Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute
8.8HIGH
CVE-2021-26804
all versions
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by chang
6.5MEDIUM
CVE-2019-15299
<= 19.04.3
An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autolog
8.8HIGH
CVE-2019-15300
>= 2.8.1 and < 2.8.30
A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/
8.8HIGH
CVE-2019-15298
>= 2.8.1 and < 2.8.30
A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configurati
8.8HIGH
CVE-2019-16406
all versions
Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual machine) fil
7.8HIGH
CVE-2019-16405
< 2.8.30
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution
7.2HIGH
CVE-2019-17105
>= 2.8 and < 2.8.27
The token generator in index.php in Centreon Web before 2.8.27 is predictable.
5.3MEDIUM
CVE-2019-17108
>= 2.8 and < 2.8.28
Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a
6.1MEDIUM
CVE-2019-17107
>= 2.8 and < 2.8.27
minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the command_hostaddr
8.8HIGH
CVE-2019-17106
<= 2.8.29
In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to e
6.5MEDIUM
CVE-2018-21023
>= 2.8 and < 2.8.28
getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter.
8.8HIGH
CVE-2018-21022
< 2.8.28
makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parameter.
8.8HIGH
CVE-2018-21021
< 2.8.27
img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter.
8.8HIGH
CVE-2018-21020
< 2.8.27
In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows attackers to
7.5HIGH
CVE-2018-11589
all versions
Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in
9.8CRITICAL
CVE-2018-11588
all versions
Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or comma
5.4MEDIUM
CVE-2018-11587
all versions
There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in cen
9.8CRITICAL
threatengine.sh