Icinga Icingaweb2 vulnerabilities
15 known vulnerabilities affecting icinga/icingaweb2.
Total CVEs
15
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM9LOW1
Vulnerabilities
Page 1 of 1
CVE-2025-27405MEDIUMCVSS 6.1fixed in 2.11.5v>= 2.12.0, < 2.12.32025-03-26
CVE-2025-27405 [MEDIUM] CWE-79 CVE-2025-27405: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vul
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5
cvelistv5nvdosv
CVE-2025-30164MEDIUMCVSS 6.1fixed in 2.11.5v>= 2.12.0, < 2.12.32025-03-26
CVE-2025-30164 [MEDIUM] CWE-601 CVE-2025-30164: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vul
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited by an authenticated user (or one that is able to authenticate), allows to manipulate the backend to redirect the user to any location
cvelistv5nvdosv
CVE-2025-27404MEDIUMCVSS 6.1fixed in 2.11.5v>= 2.12.0, < 2.12.32025-03-26
CVE-2025-27404 [MEDIUM] CWE-79 CVE-2025-27404: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vul
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5
cvelistv5nvdosv
CVE-2025-27609LOWCVSS 1.1fixed in 2.11.5v>= 2.12.0, < 2.12.32025-03-26
CVE-2025-27609 [LOW] CWE-79 CVE-2025-27609: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vul
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a request that, once transmitted to a victim's Icinga Web, allows to embed arbitrary Javascript into it and to act on behalf of that user. This issue has been resolved in versi
cvelistv5nvdosv
CVE-2022-24716HIGHCVSS 7.5PoCv>= 2.9.0, < 2.9.62022-03-08
CVE-2022-24716 [HIGH] CWE-22 CVE-2022-24716: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unaut
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database
cvelistv5nvdosv
CVE-2022-24715HIGHCVSS 8.8PoCfixed in 2.8.6v>= 2.9.0, < 2.9.62022-03-08
CVE-2022-24715 [HIGH] CWE-22 CVE-2022-24715: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authe
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade
cvelistv5nvdosv
CVE-2022-24714MEDIUMCVSS 5.3fixed in 2.8.6v>= 2.9.0, < 2.9.62022-03-08
CVE-2022-24714 [MEDIUM] CWE-863 CVE-2022-24714: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Insta
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with said roles may still have access to a collection of content. Note that
cvelistv5nvdosv
CVE-2021-32746MEDIUMCVSS 5.3v>= 2.3.0, <= 2.8.22021-07-12
CVE-2021-32746 [MEDIUM] CWE-22 CVE-2021-32746: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Betwe
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Between versions 2.3.0 and 2.8.2, the `doc` module of Icinga Web 2 allows to view documentation directly in the UI. It must be enabled manually by an administrator and users need explicit access permission to use it. Then, by visiting a certain route, it is
cvelistv5nvdosv
CVE-2021-32747MEDIUMCVSS 6.5v>= 2.0.0, <= 2.8.22021-07-12
CVE-2021-32747 [MEDIUM] CWE-200 CVE-2021-32747: Icinga Web 2 is an open source monitoring web interface, framework, and command-line interface. A vu
Icinga Web 2 is an open source monitoring web interface, framework, and command-line interface. A vulnerability in which custom variables are exposed to unauthorized users exists between versions 2.0.0 and 2.8.2. Custom variables are user-defined keys and values on configuration objects in Icinga 2. These are commonly used to reference secrets in ot
cvelistv5nvdosv
CVE-2020-24368HIGHCVSS 7.5≥ 0, < 2.8.2-12020-08-19
CVE-2020-24368 [HIGH] CVE-2020-24368: Icinga Icinga Web2 2
Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2.
osv
CVE-2018-18249CRITICALCVSS 9.8≥ 0, < 2.6.2-12018-12-17
CVE-2018-18249 [CRITICAL] CVE-2018-18249: Icinga Web 2 before 2
Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name=${PATH}_${APACHE_RUN_DIR}_${APACHE_RUN_USER} parameter to /icingaweb2/navigation/add or /icingaweb2/dashboard/new-dashlet.
osv
CVE-2018-18250HIGHCVSS 7.5≥ 0, < 2.6.2-12018-12-17
CVE-2018-18250 [HIGH] CVE-2018-18250: Icinga Web 2 before 2
Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation item.
osv
CVE-2018-18247MEDIUMCVSS 5.4≥ 0, < 2.6.2-12018-12-17
CVE-2018-18247 [MEDIUM] CVE-2018-18247: Icinga Web 2 before 2
Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter.
osv
CVE-2018-18248MEDIUMCVSS 6.1≥ 0, < 2.6.2-12018-12-17
CVE-2018-18248 [MEDIUM] CVE-2018-18248: Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/ti
Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.
osv
CVE-2018-18246MEDIUMCVSS 6.5≥ 0, < 2.6.2-12018-12-17
CVE-2018-18246 [MEDIUM] CVE-2018-18246: Icinga Web 2 before 2
Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module.
osv