Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Observium

First CVE: Sep 25, 2020Active for: 6 yearsTotal CVEs: 23
28.9
VTI Score
Low

Observium is a network monitoring and management platform deployed across IT infrastructure to collect and visualize device metrics and performance data. The vendor's vulnerability profile concentrates in its single flagship product and recurs through web-application layer weakness classes including cross-site scripting, path traversal, unrestricted file uploads, SQL injection, and cross-site request forgery—attack surfaces typical of a data-collection application that parses user input and manages file storage. A meaningful share of the vendor's disclosures reach serious severity, reflecting the administrative access and backend-database interaction inherent to monitoring platforms. Defenders should treat Observium instances as security-sensitive components, enforce strong authentication on the web interface, and prioritize updates addressing input-validation and access-control weaknesses. Current vulnerability severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
11.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Observium over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 25, 2020
5 years ago
Most Recent CVE
Jan 15, 2025
558 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-25147CRITICAL
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL
Sep 25, 20209.828NONO
CVE-2020-25132CRITICAL
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL
Sep 25, 20209.828NONO
CVE-2020-25149HIGH
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is
Sep 25, 20208.827NONO
CVE-2020-25145HIGH
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is
Sep 25, 20208.827NONO
CVE-2020-25144HIGH
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is
Sep 25, 20208.827NONO
CVE-2020-25136HIGH
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is
Sep 25, 20208.827NONO
CVE-2020-25143HIGH
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL
Sep 25, 20208.826NONO
CVE-2020-25134HIGH
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is
Sep 25, 20208.826NONO
CVE-2020-25133HIGH
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is
Sep 25, 20208.825NONO
CVE-2024-47002MEDIUM
A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted HTTP request can lead to an arbitrary html code. An authentic
Jan 15, 20255.422NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
61%
30%
9%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (43.5%)
Unknown0 (0.0%)
Required13 (56.5%)
Privileges Required
Low11 (47.8%)
High0 (0.0%)
None12 (52.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Observium.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Observium — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Observium's Products

View all 2 CNAs →

Top CWEs