VulnSea

checkmk has 5 CVEs on record between 2022 and 2026. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-79 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
Last 90 days
0 prev 2

Products

  • checkmk 5
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

checkmk vulnerabilities

CVEs affecting checkmk, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-20915Medium· 5.4
5mo ago

Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will execute in …

Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will execute in …

Sunlitcheckmk · checkmkEPSS 0.15%via NVD
CVE-2026-33276Medium· 5.4
5mo ago

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in the Uni…

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in the Uni…

Sunlitcheckmk · checkmkEPSS 0.14%via NVD
CVE-2021-40906Medium· 6.1PoC
4y ago

CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone

CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content an…

Twilightcheckmk · checkmkEPSS 0.99%via NVD
CVE-2021-40904High· 8.8PoC
4y ago

The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code

The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Success…

Midnightcheckmk · checkmkEPSS 3.7%via NVD
CVE-2021-40905High· 8.8PoC
4y ago

The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible

The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible. Successful exploitation r…

Midnightcheckmk · checkmkEPSS 3.0%via NVD
checkmk vulnerabilities (CVEs) · VulnSea