Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will execute in the browsers of other users viewing the sidebar.
References
| Link | Resource |
|---|---|
| https://checkmk.com/werk/19526 | Vendor Advisory |
Configurations
History
02 Apr 2026, 12:06
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:checkmk:checkmk:2.5.0:b1:*:*:*:*:*:* | |
| References | () https://checkmk.com/werk/19526 - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| First Time |
Checkmk
Checkmk checkmk |
31 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-31 15:16
Updated : 2026-04-02 12:06
NVD link : CVE-2026-20915
Mitre link : CVE-2026-20915
CVE.ORG link : CVE-2026-20915
JSON object : View
Products Affected
checkmk
- checkmk
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
