Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Centreon — Vulnerabilities & Security Advisories 52

Browse all 52 CVE security advisories affecting Centreon. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Centreon operates as an enterprise IT monitoring solution, primarily managing network infrastructure, servers, and applications to ensure operational continuity. Its architecture, which integrates web interfaces with backend agents, has historically exposed it to a wide array of security flaws. Among the 51 recorded Common Vulnerabilities and Exposures (CVEs), remote code execution and cross-site scripting are prevalent, often stemming from insufficient input validation in its web console. Additionally, privilege escalation vulnerabilities have allowed unauthorized users to gain administrative control, while SQL injection flaws have facilitated data exfiltration. These issues frequently arise from complex plugin architectures and legacy codebases. While recent updates have addressed critical paths, the sheer volume of past incidents highlights the challenges inherent in maintaining secure, feature-rich monitoring platforms. Organizations must prioritize regular patching and strict access controls to mitigate these persistent risks effectively.

CVE ID Title CVSS Severity Published
CVE-2025-4646 A high privilege user is able to create and use a valid admin API token in centreon-web — web CWE-863 7.2 High 2025-05-13
CVE-2025-3872 Privilege escalation by altering payload in contact form — Centreon CWE-89 7.2 High 2025-04-24
CVE-2025-3767 SQL Injection in Centreon BAM boolean KPI listing — Centreon BAM CWE-89 7.2 High 2025-04-22
CVE-2024-5725 Centreon initCurveList SQL Injection Remote Code Execution Vulnerability — Centreon CWE-89 8.8AI High AI 2024-08-21
CVE-2024-5723 Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability — Centreon CWE-89 8.8AI High AI 2024-08-21
CVE-2023-51633 Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability — Centreon CWE-79 8.8 - 2024-05-03
CVE-2024-23119 Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability — Centreon CWE-89 8.8 - 2024-04-01
CVE-2024-23118 Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability — Centreon CWE-89 8.8 - 2024-04-01
CVE-2024-23117 Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability — Centreon CWE-89 8.8 - 2024-04-01
CVE-2024-23116 Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability — Centreon CWE-89 8.8 - 2024-04-01
CVE-2024-23115 Centreon updateGroups SQL Injection Remote Code Execution Vulnerability — Centreon CWE-89 8.8 - 2024-04-01
CVE-2024-0637 Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability — Centreon CWE-89 8.8 - 2024-04-01
CVE-2022-42429 Centreon SQL注入漏洞 — Centreon CWE-89 8.8 - 2023-03-29
CVE-2022-42428 Centreon SQL注入漏洞 — Centreon CWE-89 8.8 - 2023-03-29
CVE-2022-42427 Centreon SQL注入漏洞 — Centreon CWE-89 8.8 - 2023-03-29
CVE-2022-42426 Centreon SQL注入漏洞 — Centreon CWE-89 8.8 - 2023-03-29
CVE-2022-42425 Centreon SQL注入漏洞 — Centreon CWE-89 8.8 - 2023-03-29
CVE-2022-42424 Centreon SQL注入漏洞 — Centreon CWE-89 8.8 - 2023-03-29
CVE-2022-41142 Centreon SQL注入漏洞 — Centreon CWE-89 8.8 - 2023-01-26
CVE-2022-34872 Centreon SQL注入漏洞 — Centreon CWE-89 6.5 - 2022-08-03
CVE-2022-34871 Centreon SQL注入漏洞 — Centreon CWE-89 8.8 - 2022-08-03
CVE-2012-5967 Centreon SQL注入漏洞 — Centreon 8.8 - 2012-12-19

This page lists every published CVE security advisory associated with Centreon. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.