VulnSea

zabbix vulnerabilities

CVEs whose affected-version data names the zabbix package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

12 CVEsRSS

CVE-2026-23930High· 7.5
1mo ago

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.

Twilightzabbix · zabbixEPSS 0.36%via NVD
CVE-2026-23929Medium· 5.4
1mo ago

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that trave…

Sunlitzabbix · zabbixEPSS 0.18%via NVD
CVE-2026-23922Medium· 4.9
1mo ago

The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'

The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.

Sunlitzabbix · zabbixEPSS 0.27%via NVD
CVE-2026-1199Low· 3.7
1mo ago

Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.

Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.

Sunlitzabbix · zabbixEPSS 0.16%via NVD
CVE-2026-23928Medium· 6.8
4mo ago

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a da…

Sunlitzabbix · zabbixEPSS 0.26%via NVD
CVE-2026-23927Medium· 6.5
4mo ago

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a…

Sunlitzabbix · zabbixEPSS 0.22%via NVD
CVE-2026-23926Medium· 6.8
4mo ago

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to…

Sunlitzabbix · zabbixEPSS 0.26%via NVD
CVE-2026-23924Medium· 4.9
6mo ago

Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon

Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by …

Sunlitzabbix · zabbixEPSS 0.23%via NVD
CVE-2026-23919Medium· 6.0
6mo ago

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks)

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data…

Sunlitzabbix · zabbixEPSS 0.24%via NVD
CVE-2026-23923Medium· 5.3
6mo ago

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

Sunlitzabbix · zabbixEPSS 0.27%via NVD
CVE-2026-23921High· 8.8PoC
6mo ago

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned dire…

Midnightzabbix · zabbixEPSS 3.5%via NVD
CVE-2026-23920High· 8.8
6mo ago

Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode

Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass…

Twilightzabbix · zabbixEPSS 0.30%via NVD
zabbix vulnerabilities (CVEs) · VulnSea