CVEs we hold for Centreon
Records whose assigning authority named Centreon as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-14453A user with low privileges can inject SSTI templates that can lead to RCE in open-ticketsCentreon Infra Monitoring
CVE-2025-8460A user with elevated privileges can inject XSS in the Notification rules configuration pageCentreon Infra Monitoring
CVE-2025-8459A user with low privileges can inject XSS in the Monitoring Recurrent downtimes pageCentreon Infra Monitoring
CVE-2025-8432CentreonBI user account on the MBI server can execute commands as root by modifying script runned by the CRONCentreon Infra Monitoring
CVE-2025-8430A user with elevated privileges can inject XSS in the Commands Connectors configuration configuration pageCentreon Infra Monitoring
CVE-2025-8429A user with elevated privileges can inject XSS in the ACL Action access configuration pageCentreon Infra Monitoring
CVE-2025-5965RCE via the backup feature available only to user with high privilegeCentreon Infra Monitoring
CVE-2025-5946RCE via the poller reload feature available only to user with high privilegeCentreon Infra Monitoring
CVE-2025-54893A user with elevated privileges can inject XSS in the Hosts templates configuration pageCentreon Infra Monitoring
CVE-2025-54892A user with elevated privileges can inject XSS in the SNMP traps group configuration pageCentreon Infra Monitoring
CVE-2025-54891A user with elevated privileges can inject XSS in the ACL Resource Access configuration pageCentreon Infra Monitoring
CVE-2025-54890A user with elevated privileges can inject XSS in the Hostgroups configuration pageCentreon Infra Monitoring
CVE-2025-54889A user with elevated privileges can inject XSS in the SNMP traps manufacturer configuration pageCentreon Infra Monitoring
CVE-2025-4650User with high privileges is able to introduce a SQLi using the Meta Service indicator pageCentreon web
CVE-2025-4649ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges…Centreon web
CVE-2025-4648A user with elevated privileges can inject XSS by altering the content of a SVG media during the submit request.Centreon web
CVE-2025-4647A user with elevated privileges can bypass sanitization measures by replacing the content of an existing SVGCentreon web
CVE-2025-4646A high privilege user is able to create and use a valid admin API token in centreon-webCentreon web
CVE-2025-15029An unauthenticated user is able to introduce SQL Injection using the Awie export moduleCentreon Infra Monitoring
CVE-2025-15026Unauthenticated configuration import allows administrative account creation using AWIE componentCentreon Infra Monitoring
CVE-2025-13056A user with elevated privileges can inject XSS in the Administration ACL Menus configuration pageCentreon Infra Monitoring
CVE-2025-12519Information disclosure on Administration parameters API endpointCentreon Infra Monitoring
CVE-2025-12514A user with elevated privileges is able to introduce a SQL Injection using the Open-tickets Notification rules…Centreon Infra Monitoring - Open-tickets
CVE-2025-12513A user with elevated privileges can inject XSS in the Hosts configuration parameters pageCentreon Infra Monitoring
CVE-2025-12511A user with elevated privileges can inject XSS in the DSM Administration’s Extensions configuration pageCentreon Infra Monitoring
CVE-2025-10023A user with elevated privileges can inject XSS in the Services Meta-services configuration pageCentreon Infra Monitoring
CVE-2024-23119Centreon insertGraphTemplate SQL Injection Remote Code Execution VulnerabilityCentreon
CVE-2024-23118Centreon updateContactHostCommands SQL Injection Remote Code Execution VulnerabilityCentreon
CVE-2024-23117Centreon updateContactServiceCommands SQL Injection Remote Code Execution VulnerabilityCentreon
52 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.