Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-23928

Опубликовано: 06 мая 2026
Источник: debian
EPSS Низкий

Описание

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zabbixunfixedpackage
zabbixignoredtrixiepackage
zabbixignoredbookwormpackage

Примечания

  • https://support.zabbix.com/browse/ZBX-27760

EPSS

Процентиль: 21%
0.00285
Низкий

Связанные уязвимости

ubuntu
3 месяца назад

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

nvd
3 месяца назад

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

github
3 месяца назад

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

CVSS3: 8.4
fstec
3 месяца назад

Уязвимость пользовательского интерфейса универсальной системы мониторинга Zabbix, позволяющая нарушителю выполнить произвольный JavaScript-код

CVSS3: 8.4
redos
26 дней назад

Уязвимость zabbix7.4

EPSS

Процентиль: 21%
0.00285
Низкий