« Back to list

Zabbix

Zabbix Frontend: vulnerabilities and CVEs

Zabbix Frontend has 14 published vulnerabilities, 3 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs14
Last 12 months3
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-90772High (8.3)0.36%—Sep 13, 2026
Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img…
CVE-2025-49643Medium (6)0.34%—Dec 1, 2025
An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.
CVE-2025-27232Medium (6.8)0.29%—Dec 1, 2025
An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.
CVE-2023-32725High (8.8)0.85%—Dec 18, 2023
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.
CVE-2023-30958Medium (6.1)0.40%—Aug 3, 2023
A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed. This defect was resolved with the release of Foundry Frontend 6.225.0.
CVE-2023-29457Medium (6.1)0.57%—Jul 13, 2023
Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can be sent as request to a website with a…
CVE-2023-29456Medium (5.4)0.56%—Jul 13, 2023
URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards.
CVE-2023-29455Medium (6.1)0.60%—Jul 13, 2023
Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated through a link, which sends a request to a…
CVE-2023-29454Medium (5.4)0.57%—Jul 13, 2023
Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files),…
CVE-2022-43515Critical (9.8)1.2%—Dec 5, 2022
Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it…
CVE-2022-24919Medium (4.4)1.2%—Mar 9, 2022
An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is…
CVE-2022-24918Medium (4.4)1.2%—Mar 9, 2022
An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed…
CVE-2022-24917Medium (4.4)1.2%—Mar 9, 2022
An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is…
CVE-2022-24349Medium (4.4)1.2%—Mar 9, 2022
An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059.007 JavaScript1
  2. T1189 Drive-by Compromise1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Zabbix