Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

github логотип

GHSA-qjqp-r6hf-xpqh

3 месяца назад

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

EPSS: Низкий
ubuntu логотип

CVE-2026-23928

3 месяца назад

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

EPSS: Низкий
nvd логотип

CVE-2026-23928

3 месяца назад

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

EPSS: Низкий
debian логотип

CVE-2026-23928

3 месяца назад

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in ...

EPSS: Низкий
fstec логотип

BDU:2026-06432

3 месяца назад

Уязвимость пользовательского интерфейса универсальной системы мониторинга Zabbix, позволяющая нарушителю выполнить произвольный JavaScript-код

CVSS3: 8.4
EPSS: Низкий
redos логотип

ROS-20260707-73-0003

27 дней назад

Уязвимость zabbix7.4

CVSS3: 8.4
EPSS: Низкий
redos логотип

ROS-20260707-73-0002

27 дней назад

Уязвимость zabbix7-lts

CVSS3: 8.4
EPSS: Низкий
redos логотип

ROS-20260707-73-0001

27 дней назад

Уязвимость zabbix-lts

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-qjqp-r6hf-xpqh

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-23928

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-23928

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

0%
Низкий
3 месяца назад
debian логотип
CVE-2026-23928

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in ...

0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-06432

Уязвимость пользовательского интерфейса универсальной системы мониторинга Zabbix, позволяющая нарушителю выполнить произвольный JavaScript-код

CVSS3: 8.4
0%
Низкий
3 месяца назад
redos логотип
ROS-20260707-73-0003

Уязвимость zabbix7.4

CVSS3: 8.4
0%
Низкий
27 дней назад
redos логотип
ROS-20260707-73-0002

Уязвимость zabbix7-lts

CVSS3: 8.4
0%
Низкий
27 дней назад
redos логотип
ROS-20260707-73-0001

Уязвимость zabbix-lts

CVSS3: 8.4
0%
Низкий
27 дней назад

Уязвимостей на страницу