Observium is a network monitoring and management platform deployed across IT infrastructure to collect and visualize device metrics and performance data. The vendor's vulnerability profile concentrates in its single flagship product and recurs through web-application layer weakness classes including cross-site scripting, path traversal, unrestricted file uploads, SQL injection, and cross-site request forgery—attack surfaces typical of a data-collection application that parses user input and manages file storage. A meaningful share of the vendor's disclosures reach serious severity, reflecting the administrative access and backend-database interaction inherent to monitoring platforms. Defenders should treat Observium instances as security-sensitive components, enforce strong authentication on the web interface, and prioritize updates addressing input-validation and access-control weaknesses. Current vulnerability severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Observium over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25147CRITICAL An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL | Sep 25, 2020 | 9.8 | 28 | NO | NO |
CVE-2020-25132CRITICAL An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL | Sep 25, 2020 | 9.8 | 28 | NO | NO |
CVE-2020-25149HIGH An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is | Sep 25, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-25145HIGH An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is | Sep 25, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-25144HIGH An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is | Sep 25, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-25136HIGH An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is | Sep 25, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-25143HIGH An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL | Sep 25, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-25134HIGH An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is | Sep 25, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-25133HIGH An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is | Sep 25, 2020 | 8.8 | 25 | NO | NO |
CVE-2024-47002MEDIUM A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted HTTP request can lead to an arbitrary html code. An authentic | Jan 15, 2025 | 5.4 | 22 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Observium.
Media articles that mention a CVE ID that affects a product developed by Observium — matched by CVE ID, not by vendor name.