CVE Tools

Centreon/centreon

27 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Centreon/centreon, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Centreon/centreon CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Centreon/centreon CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 27 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical415%
  • High1348%
  • Medium1037%

Latest CVEs

The 15 most recently published vulnerabilities affecting Centreon/centreon.

  1. CVE-2024-23119Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability8.8
  2. CVE-2024-23118Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability7.2
  3. CVE-2024-23117Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability7.2
  4. CVE-2024-23116Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability7.2
  5. CVE-2024-23115Centreon updateGroups SQL Injection Remote Code Execution Vulnerability7.2
  6. CVE-2024-0637Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability8.8
  7. CVE-2022-3827centreon Contact Groups Form formContactGroup.php sql injection6.3
  8. CVE-2022-40044Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability a...5.4
  9. CVE-2022-40043Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations.8.8
  10. CVE-2020-22345/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RRDdatabase_path parameter.8.8
  11. CVE-2021-27676Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Description) and dep_name (Dependency Name) parameters are vulnerable to stored X...5.4
  12. CVE-2021-28055An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user.6.5
  13. CVE-2020-10945Centreon before 19.10.7 exposes Session IDs in server responses.4.3
  14. CVE-2020-13252Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the inclu...8.8
  15. CVE-2019-16405Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location setti...7.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store