Centreon

First CVE: Apr 22, 2025Active for: 1 year
33
CVEs Published
More CVEs Published than 50% of tracked CNAs
16.5
Avg CVEs / Year
More Avg CVEs / Year than 64% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Centreon as a CNA, 90.9% affect products that Centreon develops as a vendor.

90.9%
Self-reported: 30Third-party: 3

Of all the CVEs published that affect products developed by Centreon, 24.2% are self-published by Centreon as a CNA.

24.2%
75.8%
Self-published: 30Published by other CNAs: 94

Trends Over Time

The number and severity of CVEs published by Centreon over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2025
15 months ago
Most Recent CVE
Jul 13, 2026
11 days ago

Top CVEs

All CVEs published by Centreon as a CNA, regardless of affected vendor or product.

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload setup in the configuration modu
Oct 14, 20257.247NOYES
This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is
Jul 13, 20269.641NONO
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauth
Jan 5, 20269.838NONO
In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Improper Neutralization of Special Elements used in an OS Comma
Jan 5, 20267.236NONO
Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained b
Jan 5, 20269.835NONO
Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affects Centreon Open Tickets on Cen
Feb 27, 20269.832NONO
Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (Service Dependencies modules) al
Feb 27, 20269.832NONO
Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all befor
Feb 27, 20268.830NONO
In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Improper Neutralization of Special Elements used in
Aug 22, 20258.828NONO
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring - Open-tickets (Notification rules configuration par
Dec 22, 20257.224NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA33 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network33 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None16 (48.5%)
Unknown0 (0.0%)
Required17 (51.5%)
Privileges Required
Low5 (15.2%)
High23 (69.7%)
None5 (15.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.0% of CVEs· 94th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Centreon as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Centreon as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs