No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://checkmk.com/werk/17992 |
|
Mon, 08 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicious HTML or JavaScript in changelog messages that executes in other users' browsers when they view the Activate Changes page or Audit log. | |
| Title | Fix stored XSS in global settings change log | |
| First Time appeared |
Checkmk
Checkmk checkmk |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Checkmk
Checkmk checkmk |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Checkmk
Published:
Updated: 2026-06-08T13:03:18.164Z
Reserved: 2026-05-07T11:16:47.854Z
Link: CVE-2026-8078
Updated: 2026-06-08T13:03:15.299Z
Status : Received
Published: 2026-06-08T13:16:33.760
Modified: 2026-06-08T13:16:33.760
Link: CVE-2026-8078
No data.
OpenCVE Enrichment
No data.