Zabbix
Zabbix Frontend: vulnerabilidades y CVE
Zabbix Frontend tiene 14 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses3
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-90772 | Alta (8.3) | 0.36% | — | 13 sept 2026 | Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img… |
| CVE-2025-49643 | Media (6) | 0.34% | — | 1 dic 2025 | An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service. |
| CVE-2025-27232 | Media (6.8) | 0.29% | — | 1 dic 2025 | An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss. |
| CVE-2023-32725 | Alta (8.8) | 0.85% | — | 18 dic 2023 | The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user. |
| CVE-2023-30958 | Media (6.1) | 0.40% | — | 3 ago 2023 | A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed. This defect was resolved with the release of Foundry Frontend 6.225.0. |
| CVE-2023-29457 | Media (6.1) | 0.57% | — | 13 jul 2023 | Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can be sent as request to a website with a… |
| CVE-2023-29456 | Media (5.4) | 0.56% | — | 13 jul 2023 | URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards. |
| CVE-2023-29455 | Media (6.1) | 0.60% | — | 13 jul 2023 | Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated through a link, which sends a request to a… |
| CVE-2023-29454 | Media (5.4) | 0.57% | — | 13 jul 2023 | Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files),… |
| CVE-2022-43515 | Crítica (9.8) | 1.2% | — | 5 dic 2022 | Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it… |
| CVE-2022-24919 | Media (4.4) | 1.2% | — | 9 mar 2022 | An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is… |
| CVE-2022-24918 | Media (4.4) | 1.2% | — | 9 mar 2022 | An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed… |
| CVE-2022-24917 | Media (4.4) | 1.2% | — | 9 mar 2022 | An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is… |
| CVE-2022-24349 | Media (4.4) | 1.2% | — | 9 mar 2022 | An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.