Количество 8
Количество 8
CVE-2026-23928
The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.
CVE-2026-23928
The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.
CVE-2026-23928
The Item history widget (in Zabbix 7.0+) or the Plain text widget (in ...
GHSA-qjqp-r6hf-xpqh
The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.
BDU:2026-06432
Уязвимость пользовательского интерфейса универсальной системы мониторинга Zabbix, позволяющая нарушителю выполнить произвольный JavaScript-код
ROS-20260707-73-0003
Уязвимость zabbix7.4
ROS-20260707-73-0002
Уязвимость zabbix7-lts
ROS-20260707-73-0001
Уязвимость zabbix-lts
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-23928 The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0. | 0% Низкий | 3 месяца назад | ||
CVE-2026-23928 The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0. | 0% Низкий | 3 месяца назад | ||
CVE-2026-23928 The Item history widget (in Zabbix 7.0+) or the Plain text widget (in ... | 0% Низкий | 3 месяца назад | ||
GHSA-qjqp-r6hf-xpqh The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0. | 0% Низкий | 3 месяца назад | ||
BDU:2026-06432 Уязвимость пользовательского интерфейса универсальной системы мониторинга Zabbix, позволяющая нарушителю выполнить произвольный JavaScript-код | CVSS3: 8.4 | 0% Низкий | 3 месяца назад | |
ROS-20260707-73-0003 Уязвимость zabbix7.4 | CVSS3: 8.4 | 0% Низкий | 27 дней назад | |
ROS-20260707-73-0002 Уязвимость zabbix7-lts | CVSS3: 8.4 | 0% Низкий | 27 дней назад | |
ROS-20260707-73-0001 Уязвимость zabbix-lts | CVSS3: 8.4 | 0% Низкий | 27 дней назад |
Уязвимостей на страницу