Skip to main content

Vendor/product archive

zabbix / frontend CVEs

Beta · best-effort

13 CVEs tagged to zabbix / frontend1 Critical, 0 High, 9 Medium, 3 Low, 0 Unrated.

CVE-2025-49643

Published Dec 1, 2025

An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to pot…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27232

Published Dec 1, 2025

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32725

Published Dec 18, 2023

The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the fron…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-30958

Published Aug 3, 2023

A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed. This defect was resolved with…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29457

Published Jul 13, 2023

Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29456

Published Jul 13, 2023

URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with intern…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29455

Published Jul 13, 2023

Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated thro…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29454

Published Jul 13, 2023

Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43515

Published Dec 5, 2022

Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24918

Published Mar 9, 2022

An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF tok…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1