← Vulnerability feed

Vulnerability record · CVE-2025-27405 · published 26 March 2025

CVE-2025-27405: Icinga web 2 cross-site scripting vulnerability

Icinga · Icinga Web 2

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a workaround, those who have Icinga Web 2.12.2 may enable a content security policy in the application settings.

6.1 CVSS 3.1 Medium EPSS 0.33% · top 77.0% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
0.33%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a workaround, those who have Icinga Web 2.12.2 may enable a content security policy in the application settings.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-27405 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-18249Icinga web 2 code injection vulnerabilityIcinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information …EPSS 1.5%8.8CVE-2022-24715Icinga web 2 path traversal vulnerabilityIcinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration,…EPSS 15%7.5CVE-2022-24716Icinga Web 2 unauthenticated path traversal file disclosureIcinga Web 2 fails to properly restrict path traversal, letting unauthenticated users read files on the local system that are accessible to the web-s…EPSS 89%analysed7.5CVE-2020-24368Icinga web 2 path traversal vulnerabilityIcinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files th…EPSS 3.3%7.5CVE-2018-18250Icinga web 2 injection vulnerabilityIcinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation ite…EPSS 1.00%6.5CVE-2018-18246Icinga web 2 cross-site request forgery vulnerabilityIcinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/m…EPSS 0.46%6.1CVE-2025-30164Icinga web 2 open redirect vulnerabilityIcinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.1…EPSS 0.26%6.1CVE-2025-27404Icinga web 2 cross-site scripting vulnerabilityIcinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.1…EPSS 0.60%

Source: NIST National Vulnerability Database (record CVE-2025-27405), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.