Centreon Web

Vendor:

First CVE: Jun 25, 2018 · Active for 8 years

56
Total CVEs
More Total CVEs than 98% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Centreon Web over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 25, 2018
8 years ago
Most Recent CVE
Feb 27, 2026
147 days ago

CVE Severity & Scoring

Centreon Web56 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (1.8%)
Network55 (98.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low56 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None39 (69.6%)
Unknown0 (0.0%)
Required17 (30.4%)
Privileges Required
Low19 (33.9%)
High25 (44.6%)
None12 (21.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (56 CVEs).

56 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centre
Apr 1, 20248.864NONO
Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon.
Apr 1, 20247.256NONO
Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon
Aug 21, 20248.851NONO
Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
Apr 1, 20247.250NONO
Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installati
Apr 1, 20247.248NONO
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expressi
Nov 21, 20197.248NOYES
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload setup in the configuration modu
Oct 14, 20257.247NOYES
Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cent
Apr 1, 20247.247NONO
Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cent
Aug 21, 20248.846NONO
A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x be
Aug 23, 20249.839NONO

Exploit Exposure

Signals from CVEs in this product scope (56 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.8% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.8% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (56 CVEs).

Media Mentions

Signals from CVEs in this product scope (56 CVEs).

Top CNAs Publishing CVEs For Centreon Web

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.8.2338.32.5%00
24.10.314.90.3%00
24.04.914.90.3%00
20.10.216.51.2%00
20.04.816.51.2%00
19.10.1816.51.2%00
19.04.417.80.5%00