vciy

CVEs we hold for Centreon

Records whose assigning authority named Centreon as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-2751Blind SQL InjectionCentreon Web on Central Server
CVE-2026-2750Command Injection via CLAPI generatetrapsCentreon Open Tickets on Central Server
CVE-2026-2749Path traversal in Centreon Open TicketsCentreon
CVE-2026-14453A user with low privileges can inject SSTI templates that can lead to RCE in open-ticketsCentreon Infra Monitoring
CVE-2025-8460A user with elevated privileges can inject XSS in the Notification rules configuration pageCentreon Infra Monitoring
CVE-2025-8459A user with low privileges can inject XSS in the Monitoring Recurrent downtimes pageCentreon Infra Monitoring
CVE-2025-8432CentreonBI user account on the MBI server can execute commands as root by modifying script runned by the CRONCentreon Infra Monitoring
CVE-2025-8430A user with elevated privileges can inject XSS in the Commands Connectors configuration configuration pageCentreon Infra Monitoring
CVE-2025-8429A user with elevated privileges can inject XSS in the ACL Action access configuration pageCentreon Infra Monitoring
CVE-2025-8428XSS found in the HTTP loader widgetCentreon Infra Monitoring
CVE-2025-6791Second order SQL injection available to user with low privilegeCentreon web
CVE-2025-5965RCE via the backup feature available only to user with high privilegeCentreon Infra Monitoring
CVE-2025-5946RCE via the poller reload feature available only to user with high privilegeCentreon Infra Monitoring
CVE-2025-54893A user with elevated privileges can inject XSS in the Hosts templates configuration pageCentreon Infra Monitoring
CVE-2025-54892A user with elevated privileges can inject XSS in the SNMP traps group configuration pageCentreon Infra Monitoring
CVE-2025-54891A user with elevated privileges can inject XSS in the ACL Resource Access configuration pageCentreon Infra Monitoring
CVE-2025-54890A user with elevated privileges can inject XSS in the Hostgroups configuration pageCentreon Infra Monitoring
CVE-2025-54889A user with elevated privileges can inject XSS in the SNMP traps manufacturer configuration pageCentreon Infra Monitoring
CVE-2025-4650User with high privileges is able to introduce a SQLi using the Meta Service indicator pageCentreon web
CVE-2025-4649ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges…Centreon web
CVE-2025-4648A user with elevated privileges can inject XSS by altering the content of a SVG media during the submit request.Centreon web
CVE-2025-4647A user with elevated privileges can bypass sanitization measures by replacing the content of an existing SVGCentreon web
CVE-2025-4646A high privilege user is able to create and use a valid admin API token in centreon-webCentreon web
CVE-2025-3872Privilege escalation by altering payload in contact formCentreon
CVE-2025-3767SQL Injection in Centreon BAM boolean KPI listingCentreon BAM
CVE-2025-15029An unauthenticated user is able to introduce SQL Injection using the Awie export moduleCentreon Infra Monitoring
CVE-2025-15026Unauthenticated configuration import allows administrative account creation using AWIE componentCentreon Infra Monitoring
CVE-2025-13056A user with elevated privileges can inject XSS in the Administration ACL Menus configuration pageCentreon Infra Monitoring
CVE-2025-12519Information disclosure on Administration parameters API endpointCentreon Infra Monitoring
CVE-2025-12514A user with elevated privileges is able to introduce a SQL Injection using the Open-tickets Notification rules…Centreon Infra Monitoring - Open-tickets
CVE-2025-12513A user with elevated privileges can inject XSS in the Hosts configuration parameters pageCentreon Infra Monitoring
CVE-2025-12511A user with elevated privileges can inject XSS in the DSM Administration’s Extensions configuration pageCentreon Infra Monitoring
CVE-2025-10023A user with elevated privileges can inject XSS in the Services Meta-services configuration pageCentreon Infra Monitoring
CVE-2024-5725Centreon initCurveList SQL Injection Remote Code Execution VulnerabilityCentreon
CVE-2024-5723Centreon updateServiceHost SQL Injection Remote Code Execution VulnerabilityCentreon
CVE-2024-23119Centreon insertGraphTemplate SQL Injection Remote Code Execution VulnerabilityCentreon
CVE-2024-23118Centreon updateContactHostCommands SQL Injection Remote Code Execution VulnerabilityCentreon
CVE-2024-23117Centreon updateContactServiceCommands SQL Injection Remote Code Execution VulnerabilityCentreon
CVE-2024-23116Centreon updateLCARelation SQL Injection Remote Code Execution VulnerabilityCentreon
CVE-2024-23115Centreon updateGroups SQL Injection Remote Code Execution VulnerabilityCentreon
CVE-2024-0637Centreon updateDirectory SQL Injection Remote Code Execution VulnerabilityCentreon
CVE-2023-51633Centreon sysName Cross-Site Scripting Remote Code Execution VulnerabilityCentreon
CVE-2022-42429no title heldCentreon
CVE-2022-42428no title heldCentreon
CVE-2022-42427no title heldCentreon
CVE-2022-42426no title heldCentreon
CVE-2022-42425no title heldCentreon
CVE-2022-42424no title heldCentreon
CVE-2022-41142no title heldCentreon
CVE-2022-34872no title heldCentreon
CVE-2022-34871no title heldCentreon
CVE-2012-5967no title heldCentreon; Centreon web

52 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.