Debian Zabbix vulnerabilities
114 known vulnerabilities affecting debian/zabbix.
Total CVEs
114
CISA KEV
1
actively exploited
Public exploits
18
Exploited in wild
2
Severity breakdown
CRITICAL16HIGH23MEDIUM41LOW34
Vulnerabilities
Page 2 of 6
CVE-2024-36467P3HIGHCVSS 7.5fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-36467 [HIGH] CVE-2024-36467: zabbix - An authenticated user with API access (e.g.: user with default User role), more ...
An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having restricted GUI access.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+d
debian
CVE-2014-3005P3CRITICALCVSS 9.8fixed in zabbix 1:2.2.5+dfsg-1 (bookworm)2014
CVE-2014-3005 [CRITICAL] CVE-2014-3005: zabbix - XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x ...
XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.
Scope: local
bookworm: resolved (fixed in 1:2.2.5+dfsg-1)
bullseye: resolved (fixed in 1:2.2.5+dfsg-
debian
CVE-2026-23921P3HIGHCVSS 8.7fixed in zabbix 1:7.0.22+dfsg-1 (forky)2026
CVE-2026-23921 [HIGH] CVE-2026-23921: zabbix - A low privilege Zabbix user with API access can exploit a blind SQL injection vu...
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier di
debian
CVE-2013-3738P3CRITICALCVSS 9.8fixed in zabbix 1:2.0.7+dfsg-1 (bookworm)2013
CVE-2013-3738 [CRITICAL] CVE-2013-3738: zabbix - A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitiza...
A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 1:2.0.7+dfsg-1)
bullseye: resolved (fixed in 1:2.0.7+dfsg-1)
forky: resolved (fixed in 1:2.0.7+dfsg-1)
sid: resolved (fixed in 1:2.0.7+dfsg-1
debian
CVE-2023-29452P3MEDIUMCVSS 5.5fixed in zabbix 1:6.0.23+dfsg-1 (forky)2023
CVE-2023-29452 [MEDIUM] CVE-2023-29452: zabbix - Currently, geomap configuration (Administration -> General -> Geographical maps)...
Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Other” Tile provider.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 1:6.0.23+dfsg-1)
sid: resolved (fixed in 1:6.0.23+dfsg-1)
trixie: resolved (fixed in 1:6.0.23+dfsg-1)
debian
CVE-2022-46768P3MEDIUMCVSS 5.9fixed in zabbix 1:6.0.13+dfsg-1 (bookworm)2022
CVE-2022-46768 [MEDIUM] CVE-2022-46768: zabbix - Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation...
Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.
Scope: local
bookworm: resolved (fixed in 1:6.0.13+dfsg-1)
bullseye: resolved
forky: resolved (fixed in 1:6.0.13+dfsg-1)
sid: resolved (fixed in 1:6.0.13+dfsg-1)
t
debian
CVE-2024-36466P3HIGHCVSS 8.8fixed in zabbix 1:7.0.1+dfsg-1 (forky)2024
CVE-2024-36466 [HIGH] CVE-2024-36466: zabbix - A bug in the code allows an attacker to sign a forged zbx_session cookie, which ...
A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 1:7.0.1+dfsg-1)
sid: resolved (fixed in 1:7.0.1+dfsg-1)
trixie: resolved (fixed in 1:7.0.1+dfsg-1)
debian
CVE-2024-36463P3MEDIUMCVSS 6.5fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-36463 [MEDIUM] CVE-2024-36463: zabbix - The implementation of atob in "Zabbix JS" allows to create a string with arbitra...
The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1)
forky: resolved (fixed in 1:7.0.3+dfsg-1)
sid: resolved (fixed in 1:7.0.3+dfsg-1)
trixie: resolved (fixed in 1:7.0.3+dfsg-1)
debian
CVE-2025-27240P3HIGHCVSS 7.5fixed in zabbix 1:7.0.5+dfsg-1 (forky)2025
CVE-2025-27240 [HIGH] CVE-2025-27240: zabbix - A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts b...
A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 1:7.0.5+dfsg-1)
sid: resolved (fixed in 1:7.0.5+dfsg-1)
trixie: resolved (fixed in 1:7.0.5+dfsg-1)
debian
CVE-2024-42330P3CRITICALCVSS 9.1fixed in zabbix 1:5.0.45+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-42330 [CRITICAL] CVE-2024-42330: zabbix - The HttpRequest object allows to get the HTTP headers from the server's response...
The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create internal strings that can be used to access hidden properties of objects.
Scope: local
boo
debian
CVE-2009-4501P4MEDIUMCVSS 5.0PoCfixed in zabbix 1:1.8-1 (bookworm)2009
CVE-2009-4501 [MEDIUM] CVE-2009-4501: zabbix - The zbx_get_next_field function in libs/zbxcommon/str.c in Zabbix Server before ...
The zbx_get_next_field function in libs/zbxcommon/str.c in Zabbix Server before 1.6.8 allows remote attackers to cause a denial of service (crash) via a request that lacks expected separators, which triggers a NULL pointer dereference, as demonstrated using the Command keyword.
Scope: local
bookworm: resolved (fixed in 1:1.8-1)
bullseye: resolved (fixed in 1:1.8-1)
f
debian
CVE-2026-23925P3MEDIUMCVSS 5.1fixed in zabbix 1:7.0.22+dfsg-1 (forky)2026
CVE-2026-23925 [MEDIUM] CVE-2026-23925: zabbix - An authenticated Zabbix user (User role) with template/host write permissions is...
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
Scope: local
bookworm: open
bullseye: open
f
debian
CVE-2013-6824P3LOWCVSS 7.5fixed in zabbix 1:2.2.0+dfsg-6 (bookworm)2013
CVE-2013-6824 [HIGH] CVE-2013-6824: zabbix - Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows re...
Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in a flexible user parameter.
Scope: local
bookworm: resolved (fixed in 1:2.2.0+dfsg-6)
bullseye: resolved (fixed in 1:2.2.0+dfsg-6)
forky: resolved (fixed in 1:2.2.0+dfsg-6)
sid: resolved (fixed in 1:2.2.0+dfsg-6)
debian
CVE-2024-22116P3CRITICALCVSS 9.9fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-22116 [CRITICAL] CVE-2024-22116: zabbix - An administrator with restricted permissions can exploit the script execution fu...
An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+de
debian
CVE-2023-29453P3LOWCVSS 9.8fixed in zabbix 1:6.0.23+dfsg-1 (forky)2023
CVE-2023-29453 [CRITICAL] CVE-2023-29453: zabbix - Templates do not properly consider backticks (`) as Javascript string delimiters...
Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into th
debian
CVE-2023-32724P3CRITICALCVSS 9.1fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2023
CVE-2023-32724 [CRITICAL] CVE-2023-32724: zabbix - Memory pointer is in a property of the Ducktape object. This leads to multiple v...
Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1)
forky: resolved (fixed in 1:6.0.23+dfsg-1)
sid: resolved (fixed in 1:6.0.23+dfsg-1)
trixie: resolved (fixed in 1:6.0.23+dfsg-1)
debian
CVE-2026-23920P3HIGHCVSS 7.7fixed in zabbix 1:7.0.22+dfsg-1 (forky)2026
CVE-2026-23920 [HIGH] CVE-2026-23920: zabbix - Host and event action script input is validated with a regex (set by the adminis...
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:7.0.22+dfsg-1)
sid: res
debian
CVE-2024-36461P3CRITICALCVSS 9.1fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-36461 [CRITICAL] CVE-2024-36461: zabbix - Within Zabbix, users have the ability to directly modify memory pointers in the ...
Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u1)
forky: resolved (fixed in 1:7.0.1+dfsg-1)
sid: resolved (fixed in 1:7.0.1+dfsg-1)
trixie: resolved (fixed in 1:7.0.1+dfsg-1)
debian
CVE-2014-9450P3HIGHCVSS 7.5fixed in zabbix 1:2.2.7+dfsg-2 (bookworm)2014
CVE-2014-9450 [HIGH] CVE-2014-9450: zabbix - Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbi...
Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbix before 1.8.22, 2.0.x before 2.0.14, and 2.2.x before 2.2.8 allow remote attackers to execute arbitrary SQL commands via the (1) itemid or (2) periods parameter.
Scope: local
bookworm: resolved (fixed in 1:2.2.7+dfsg-2)
bullseye: resolved (fixed in 1:2.2.7+dfsg-2)
forky: resolved (fixed in
debian
CVE-2021-27927P3HIGHCVSS 8.8fixed in zabbix 1:5.0.8+dfsg-1 (bookworm)2021
CVE-2021-27927 [HIGH] CVE-2021-27927: zabbix - In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x befor...
In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the init() method. An attacker doesn't have to know Zabbix user login credentials, but has to k
debian