Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2859 articles · 109792 vulns · 38/41 feeds (7d)
← Back to list
5.4
CVE-2025-64999
checkmk · checkmk

Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker that can manipulate a host's check output to inject malicious JavaScript into t

Description

Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker that can manipulate a host's check output to inject malicious JavaScript into the Synthetic Monitoring HTML logs, which can then be accessed via a crafted phishing link.

Affected Products

VendorProductVersions
checkmkcheckmk—

References

  • https://checkmk.com/werk/19238(Vendor Advisory)
  • https://github.com/sbaresearch/advisories/tree/e72ce9bb6b9ffffc1fc35e4d8152ad153293c851/2025/SBA-ADV-20251118-01_Checkmk_Cross_Site_Scripting
CVSS 3.15.4 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-79
PublishedFeb 26, 2026
Last enriched8d ago
Trending Score0
Source articles0
Independent0
Info Completeness7/14
Missing: versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-33457EXP
Potential livestatus injection in prediction graph page
Trending: 60
NONECVE-2026-33456EXP
Potential livestatus injection in notification test
Trending: 60
NONECVE-2026-33455EXP
Livestatus injection in monitoring quicksearch
Trending: 60
NONECVE-2026-3466
Cross-site scripting in dashlet title
Trending: 24
NONECVE-2025-39666
omd: Local privilege escalation when executing omd commands as root
Trending: 24

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Feb 26, 2026
Discovered by ZDM
Apr 1, 2026