All 70 CVE vulnerabilities found in Zabbix, with AI-generated Chinese analysis, references, and POCs.
This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with the Zabbix monitoring software product. It serves as a comprehensive resource for security researchers and system administrators seeking to understand the historical and current security posture of this widely used open-source enterprise monitoring solution. The content on this page aggregates vulnerability data covering various release versions of Zabbix, ranging from older legacy releases to the most recent stable updates. This collection includes diverse weakness types such as cross-site scripting, improper input validation, and privilege escalation flaws that have been publicly disclosed or identified by the vendor and security community. By centralizing this information, the page provides a structured view of the security issues affecting the product over time, allowing users to see patterns in how certain weakness classes have manifested across different product iterations. Users can utilize this resource to track official vendor advisories and security notices issued by the Zabbix team. The page facilitates a deeper understanding of specific weakness classes within the context of the product’s architecture and functionality. Additionally, it enables users to look up the complete vulnerability history of Zabbix, helping them assess risk exposure, prioritize patching efforts, and verify whether specific versions are affected by known security flaws. This systematic approach ensures that stakeholders have immediate access to critical security context without needing to search through disparate sources or release notes individually.
Vendor: Zabbix
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2023-29456 | Inefficient URL schema validation CWE-20 | 5.7 | Medium | 2023-07-13 |
| CVE-2023-29455 | Reflected XSS in several fields of graph form CWE-20 | 5.4 | Medium | 2023-07-13 |
| CVE-2023-29454 | Persistent XSS in the user form CWE-20 | 5.4 | Medium | 2023-07-13 |
| CVE-2023-29452 | Remove possibility to add html into Geomap attribution field CWE-20 | 5.5 | Medium | 2023-07-13 |
| CVE-2023-29451 | Denial of service caused by a bug in the JSON parser CWE-20 | 4.7 | Medium | 2023-07-13 |
| CVE-2023-29450 | Unauthorized limited filesystem access from preprocessing CWE-200 | 8.5 | High | 2023-07-13 |
| CVE-2023-29449 | Limited control of resource utilization in JS preprocessing CWE-400 | 5.9 | Medium | 2023-07-13 |
| CVE-2013-3628 | Zabbix 注入漏洞 | 8.8 | - | 2020-02-07 |
| CVE-2017-2825 | Zabbix Server 安全漏洞 | 7.0 | - | 2018-04-20 |
| CVE-2017-2826 | Zabbix Server 信息泄露漏洞 | 7.5 | - | 2018-04-09 |
All 70 known CVE vulnerabilities affecting Zabbix with full Chinese analysis, references, and POCs where available.