Zabbix

First CVE: Jan 13, 2022Active for: 5 years
81
CVEs Published
More CVEs Published than 67% of tracked CNAs
16.2
Avg CVEs / Year
More Avg CVEs / Year than 63% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 23% of tracked CNAs
2.5%
In CISA KEV
Higher KEV Rate than 93% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Zabbix as a CNA, 100.0% affect products that Zabbix develops as a vendor.

100.0%
Self-reported: 81Third-party: 0

Of all the CVEs published that affect products developed by Zabbix, 63.3% are self-published by Zabbix as a CNA.

63.3%
36.7%
Self-published: 81Published by other CNAs: 47

Trends Over Time

The number and severity of CVEs published by Zabbix over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 13, 2022
4 years ago
Most Recent CVE
May 6, 2026
79 days ago

Top CVEs

All CVEs published by Zabbix as a CNA, regardless of affected vendor or product.

81 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session w
Jan 13, 20229.897YESYES
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step ch
Jan 13, 20225.394YESYES
A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser
Nov 27, 20249.984NOYES
Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is
May 17, 20248.880NOYES
Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Other” Tile provider.
Jul 13, 20235.448NONO
Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters be
Dec 15, 20225.945NONO
A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy p
Apr 2, 20258.842NONO
The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perfor
May 6, 20267.330NONO
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in
May 6, 20267.330NONO
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfiel
Mar 24, 20268.730NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA81 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local8 (9.9%)
Network66 (81.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (4.9%)
Attack Complexity
Low71 (87.7%)
High10 (12.3%)
Unknown0 (0.0%)
User Interaction
None61 (75.3%)
Unknown0 (0.0%)
Required18 (22.2%)
Privileges Required
Low38 (46.9%)
High19 (23.5%)
None24 (29.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (81 CVEs).

CISA KEV
2 CVEs
2.5% of CVEs· 93rd percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
3.7% of CVEs· 90th percentile
ExploitDB
1 CVE
1.2% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Zabbix as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Zabbix as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs