Icinga Web 2 vulnerabilities
13 known vulnerabilities affecting icinga/icinga_web_2.
Total CVEs
13
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM7LOW1
Vulnerabilities
Page 1 of 1
CVE-2025-27405MEDIUMCVSS 6.1fixed in 2.11.5≥ 2.12.0, < 2.12.32025-03-26
CVE-2025-27405 [MEDIUM] CWE-79 CVE-2025-27405: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vul
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5
nvd
CVE-2025-30164MEDIUMCVSS 6.1fixed in 2.11.5≥ 2.12.0, < 2.12.32025-03-26
CVE-2025-30164 [MEDIUM] CWE-601 CVE-2025-30164: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vul
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited by an authenticated user (or one that is able to authenticate), allows to manipulate the backend to redirect the user to any location
nvd
CVE-2025-27404MEDIUMCVSS 6.1fixed in 2.11.5≥ 2.12.0, < 2.12.32025-03-26
CVE-2025-27404 [MEDIUM] CWE-79 CVE-2025-27404: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vul
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5
nvd
CVE-2025-27609LOWCVSS 1.1fixed in 2.11.5≥ 2.12.0, < 2.12.32025-03-26
CVE-2025-27609 [LOW] CWE-79 CVE-2025-27609: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vul
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a request that, once transmitted to a victim's Icinga Web, allows to embed arbitrary Javascript into it and to act on behalf of that user. This issue has been resolved in versi
nvd
CVE-2022-24716HIGHCVSS 7.5PoC≥ 2.9.0, < 2.9.62022-03-08
CVE-2022-24716 [HIGH] CWE-22 CVE-2022-24716: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unaut
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database
nvd
CVE-2022-24715HIGHCVSS 8.8PoCfixed in 2.8.6≥ 2.9.0, < 2.9.62022-03-08
CVE-2022-24715 [HIGH] CWE-22 CVE-2022-24715: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authe
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade
nvd
CVE-2022-24714MEDIUMCVSS 5.3fixed in 2.8.6≥ 2.9.0, < 2.9.62022-03-08
CVE-2022-24714 [MEDIUM] CWE-863 CVE-2022-24714: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Insta
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with said roles may still have access to a collection of content. Note that
nvd
CVE-2020-24368HIGHCVSS 7.5≥ 2.0.0, < 2.6.4≥ 2.7.0, < 2.7.4+1 more2020-08-19
CVE-2020-24368 [HIGH] CWE-22 CVE-2020-24368: Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability whic
Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2.
nvd
CVE-2018-18249CRITICALCVSS 9.8fixed in 2.6.22018-12-17
CVE-2018-18249 [CRITICAL] CWE-94 CVE-2018-18249: Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environm
Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name=${PATH}_${APACHE_RUN_DIR}_${APACHE_RUN_USER} parameter to /icingaweb2/navigation/add or /icingaweb2/dashboard/new-dashlet.
nvd
CVE-2018-18250HIGHCVSS 7.5fixed in 2.6.22018-12-17
CVE-2018-18250 [HIGH] CWE-74 CVE-2018-18250: Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a sin
Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation item.
nvd
CVE-2018-18247MEDIUMCVSS 5.4fixed in 2.6.22018-12-17
CVE-2018-18247 [MEDIUM] CWE-79 CVE-2018-18247: Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter.
Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter.
nvd
CVE-2018-18248MEDIUMCVSS 6.1v2.6.12018-12-17
CVE-2018-18248 [MEDIUM] CWE-79 CVE-2018-18248: Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/use
Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.
nvd
CVE-2018-18246MEDIUMCVSS 6.5fixed in 2.6.22018-12-17
CVE-2018-18246 [MEDIUM] CWE-352 CVE-2018-18246: Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable t
Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module.
nvd