Where
-Infinity
0

Centreon centreon-open-ticketsA user with low privileges can inject SSTI templates that can lead to RCE in open-tickets

Risk 68
Severity
9.6
First published (updated )

Centreon Open TicketsPath traversal in Centreon Open Tickets

Risk 59
Severity
9.9
EPSS
0.03%
First published (updated )

Centreon WebCommand Injection via CLAPI generatetraps

Risk 61
Severity
9.8
EPSS
0.04%
First published (updated )

Centreon Centreon WebBlind SQL Injection

Risk 61
Severity
9.8
EPSS
0.02%
First published (updated )

Centreon Centreon Infra MonitoringBlind SQL Injection

Risk 39
Severity
8.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Centreon AwieAn unauthenticated user is able to introduce SQL Injection using the Awie export module

Risk 86
Severity
9.8
First published (updated )

Centreon Infra MonitoringUnauthenticated configuration import allows administrative account creation using AWIE component

Risk 86
Severity
9.8
First published (updated )

Centreon Dynamic Service ManagementA user with elevated privileges can inject XSS in the DSM Administration’s Extensions configuration page

Risk 37
Severity
6.8
First published (updated )

Centreon Centreon WebA user with elevated privileges can inject XSS in the Hosts configuration parameters page

Risk 37
Severity
6.8
First published (updated )

Centreon Centreon WebInformation disclosure on Administration parameters API endpoint

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Centreon Centreon WebA user with elevated privileges can inject XSS in the Administration ACL Menus configuration page

Risk 37
Severity
6.8
First published (updated )

Centreon Centreon WebRCE via the backup feature available only to user with high privilege

Risk 66
Severity
7.2
First published (updated )

Centreon Centreon WebA user with elevated privileges can inject XSS in the Hostgroups configuration page

Risk 37
Severity
6.8
First published (updated )

Centreon Open TicketsA user with elevated privileges is able to introduce a SQL Injection using the Open-tickets Notification rules configuration parameters

Risk 66
Severity
7.2
First published (updated )

Centreon Open TicketsA user with elevated privileges can inject XSS in the Notification rules configuration page

Risk 37
Severity
6.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Centreon Centreon WebA user with elevated privileges can inject XSS in the Services Meta-services configuration page

Risk 33
Severity
6.2
First published (updated )

Centreon Infra MonitoringCentreonBI user account on the MBI server can execute commands as root by modifying script runned by the CRON

Risk 66
Severity
8.4
First published (updated )

Centreon Centreon WebA user with low privileges can inject XSS in the Monitoring Recurrent downtimes page

Risk 44
Severity
7.7
First published (updated )

Centreon Centreon WebA user with elevated privileges can inject XSS in the Commands Connectors configuration configuration page

Risk 37
Severity
6.8
First published (updated )

Centreon Centreon WebA user with elevated privileges can inject XSS in the ACL Action access configuration page

Risk 37
Severity
6.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Centreon Centreon WebA user with elevated privileges can inject XSS in the Hosts templates configuration page

Risk 37
Severity
6.8
First published (updated )

Centreon Centreon WebA user with elevated privileges can inject XSS in the ACL Resource Access configuration page

Risk 37
Severity
6.8
First published (updated )

Centreon Centreon WebA user with elevated privileges can inject XSS in the SNMP traps group configuration page

Risk 37
Severity
6.8
First published (updated )

Centreon Centreon WebA user with elevated privileges can inject XSS in the SNMP traps manufacturer configuration page

Risk 37
Severity
6.8
First published (updated )

Centreon Centreon WebRCE via the poller reload feature available only to user with high privilege

Risk 66
Severity
7.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Centreon Centreon WebXSS found in the HTTP loader widget

Risk 38
Severity
6.8
First published (updated )

Centreon Centreon WebSecond order SQL injection available to user with low privilege

Risk 79
Severity
8.8
First published (updated )

Centreon Centreon WebUser with high privileges is able to introduce a SQLi using the Meta Service indicator page

Risk 66
Severity
7.2
First published (updated )

Centreon Centreon WebACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs.

Risk 22
Severity
4.9
EPSS
0.02%
First published (updated )

Centreon Centreon WebA user with elevated privileges can inject XSS by altering the content of a SVG media during the submit request.

Risk 50
Severity
8.4
EPSS
0.01%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203