Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Frontend — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Frontend, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation index for the Frontend product category, covering various weakness types and associated tags. It collects and organizes security reports related to common frontend development issues, including but not limited to cross-site scripting, insecure data handling, and client-side logic flaws. The database spans vulnerability records from 2015 to the present, ensuring a comprehensive historical view of security trends in web and mobile frontend technologies. Here, security professionals and developers can track a vendor's advisories to stay informed about patch availability and recommended mitigation strategies. You can also understand a weakness class by analyzing multiple instances of the same flaw across different platforms, revealing common patterns and root causes. Additionally, the page allows users to look up a product's vulnerability history, providing a chronological timeline of reported issues and their resolution status. This structured approach facilitates deeper analysis of security postures and helps identify systemic risks in frontend architectures. By aggregating data from multiple sources, the page offers a unified view that simplifies the process of monitoring and responding to frontend security threats. Whether you are conducting a risk assessment, preparing for an audit, or seeking to improve coding practices, this resource serves as a foundational reference for understanding the landscape of frontend vulnerabilities. The content is continuously updated to reflect the latest findings and industry standards.

Vendor: Zabbix

CVE IDTitleCVSSSeverityPublished
CVE-2025-64758 @dependencytrack/frontend Vulnerable to Persistent Cross-Site-Scripting via Welcome Message CWE-79 4.8 Medium2025-11-17
CVE-2022-43515 X-Forwarded-For header is active by default causes access to Zabbix sites in maintenance mode CWE-20 5.3 Medium2022-12-12
CVE-2022-39350 @dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability Details CWE-79 5.4 Medium2022-10-25
CVE-2022-40626 Reflected XSS in the backurl parameter of Zabbix Frontend CWE-79 4.8 Medium2022-09-14
CVE-2022-35230 Reflected XSS in graphs page of Zabbix Frontend CWE-79 3.7 Low2022-07-06
CVE-2022-35229 Reflected XSS in discovery page of Zabbix Frontend CWE-79 3.7 Low2022-07-06
CVE-2022-24919 Reflected XSS in graph configuration window of Zabbix Frontend CWE-79 3.7 Low2022-03-09
CVE-2022-24918 Reflected XSS in item configuration window of Zabbix Frontend CWE-79 3.7 Low2022-03-09
CVE-2022-24917 Reflected XSS in service configuration window of Zabbix Frontend CWE-79 3.7 Low2022-03-09
CVE-2022-24349 Reflected XSS in action configuration window of Zabbix Frontend CWE-79 4.6 Medium2022-03-09
CVE-2022-23134 Possible view of the setup pages by unauthenticated users if config file already exists CWE-284 3.7 Low2022-01-13
CVE-2022-23133 Stored XSS in host groups configuration window in Zabbix Frontend CWE-79 6.3 Medium2022-01-13
CVE-2022-23131 Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML CWE-290 9.1 Critical2022-01-13

All 13 known CVE vulnerabilities affecting Frontend with full Chinese analysis, references, and POCs where available.