Icinga Web 2
Vendor:
First CVE: Dec 17, 2018 · Active for 7 years
13
Total CVEs
More Total CVEs than 91% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Icinga Web 2 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 17, 2018
7 years ago
Most Recent CVE
Mar 26, 2025
486 days ago
CVE Severity & Scoring
Icinga Web 213 CVEs
62%
31%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (46.2%)
Unknown0 (0.0%)
Required7 (53.8%)
Privileges Required
Low3 (23.1%)
High0 (0.0%)
None10 (76.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24716HIGH Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible t | Mar 8, 2022 | 7.5 | 87 | NO | YES |
CVE-2022-24715HIGH Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files | Mar 8, 2022 | 8.8 | 47 | NO | YES |
CVE-2018-18249CRITICAL Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name | Dec 17, 2018 | 9.8 | 28 | NO | NO |
CVE-2020-24368HIGH Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process | Aug 19, 2020 | 7.5 | 26 | NO | NO |
CVE-2018-18250HIGH Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation item. | Dec 17, 2018 | 7.5 | 23 | NO | NO |
CVE-2025-27405MEDIUM Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a | Mar 26, 2025 | 6.1 | 22 | NO | NO |
CVE-2022-24714MEDIUM Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use servic | Mar 8, 2022 | 5.3 | 21 | NO | NO |
CVE-2018-18246MEDIUM Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enabl | Dec 17, 2018 | 6.5 | 21 | NO | NO |
CVE-2018-18248MEDIUM Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /i | Dec 17, 2018 | 6.1 | 20 | NO | NO |
CVE-2025-30164MEDIUM Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attac | Mar 26, 2025 | 6.1 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.7% of CVEs· 97th percentile
Nuclei
1 CVE
7.7% of CVEs· 97th percentile
ExploitDB
2 CVEs
15.4% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Icinga Web 2
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.6.1 | 1 | 6.1 | 0.7% | 0 | 0 |