Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Checkmk GmbH

First CVE: Oct 2, 2017Active for: 9 yearsTotal CVEs: 111
34.4
VTI Score
Medium

Checkmk GmbH maintains a focused monitoring and observability platform that, despite its narrow product scope, occupies a prominent position in enterprise IT operations infrastructure. The vendor's vulnerability footprint concentrates within its core Checkmk product and is characterized by web-application-oriented weakness classes including cross-site scripting variants, input-validation flaws, and improper handling of sensitive information in logs—typical of browser-facing configuration and dashboard interfaces. The durable pattern reflects the challenge of securing feature-rich web UIs that handle both user input and system data across distributed monitoring deployments. Current exposure counts, severity breakdown, and exploitation activity are shown alongside this summary.

FAUCET AI Generated
111
Total CVEs
More Total CVEs than 99% of tracked vendors
15.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Checkmk GmbH over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 2, 2017
8 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Self-Reporting Analysis

Of all the CVEs published by Checkmk GmbH as a CNA, 86.1% affect products that Checkmk GmbH develops as a vendor.

86.1%
13.9%
Self-reported: 99 (86.1%)
Third-party: 16 (13.9%)

Of all the CVEs published that affect products developed by Checkmk GmbH, 89.2% are self-published by Checkmk GmbH as a CNA.

89.2%
10.8%
Self-published: 99 (89.2%)
Other CNAs: 12 (10.8%)

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (111 CVEs).

111 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-14955MEDIUM
Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user informat
Oct 2, 20175.937NOYES
CVE-2021-40905HIGH
The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making
Mar 25, 20228.832NONO
CVE-2021-40904HIGH
The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code
Mar 25, 20228.832NONO
CVE-2026-33456HIGH
Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Live
Apr 10, 20267.630NONO
CVE-2024-47091HIGH
Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able to create a Windows service whos
May 13, 20267.829NONO
CVE-2022-48317CRITICAL
Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when commu
Feb 20, 20239.829NONO
CVE-2022-46836HIGH
PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP
Feb 20, 20238.829NONO
CVE-2026-24096HIGH
Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 allows low-privileged
Apr 1, 20268.828NONO
CVE-2026-8593MEDIUM
Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and
Jul 21, 20265.327NONO
CVE-2026-14852MEDIUM
Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows a local unprivileged user to execute arbitrary c
Jul 14, 20265.227NONO
View all 111 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products111 CVEs
56%
37%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local28 (25.2%)
Network83 (74.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low108 (97.3%)
High3 (2.7%)
Unknown0 (0.0%)
User Interaction
None78 (70.3%)
Unknown0 (0.0%)
Required33 (29.7%)
Privileges Required
Low71 (64.0%)
High11 (9.9%)
None29 (26.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (111 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.9% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Checkmk GmbH.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Checkmk GmbH — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Checkmk GmbH's Products

View all 2 CNAs →

Top CWEs