« Back to list

It-novum

It-novum Openitcockpit: vulnerabilities and CVEs

It-novum Openitcockpit has 17 published vulnerabilities, 3 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.

CVEs17
Last 12 months3
Critical4
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-24893High (8.8)1.4%—Apr 14, 2026
openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user…
CVE-2026-24892High (8.8)0.83%—Feb 20, 2026
openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization pattern…
CVE-2026-24891High (7.5)0.36%—Feb 20, 2026
openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearman worker…
CVE-2023-3520Medium (4.6)0.30%—Jul 6, 2023
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6.
CVE-2023-36663High (8.8)0.71%—Jun 25, 2023
it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface.
CVE-2023-3218Medium (4.4)0.47%—Jun 13, 2023
Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5.
CVE-2020-10788Critical (9.1)1.6%—Mar 25, 2020
openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections.
CVE-2020-10791Medium (6.5)1.2%—Mar 25, 2020
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka…
CVE-2020-10790Medium (5.4)0.91%—Mar 25, 2020
openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.
CVE-2020-10789Critical (9.8)2.0%—Mar 25, 2020
openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php.
CVE-2020-10792High (7.5)1.9%—Mar 20, 2020
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
CVE-2019-10227Medium (6.1)1.2%—Dec 31, 2019
openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.
CVE-2019-15494Critical (9.8)1.5%—Aug 23, 2019
openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.
CVE-2019-15493High (7.5)1.2%—Aug 23, 2019
openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21.
CVE-2019-15492Medium (6.1)0.82%—Aug 23, 2019
openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.
CVE-2019-15491High (8.8)0.60%—Aug 23, 2019
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.
CVE-2019-15490Critical (9.8)1.7%—Aug 23, 2019
openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter3
  2. T1210 Exploitation of Remote Services3

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.