CVE-2025-39663

Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3.0p39, 2.2.0 and 2.1.0 (eol).
CVSS

No CVSS.

Configurations

No configuration.

History

30 Oct 2025, 14:15

Type Values Removed Values Added
References () https://github.com/sbaresearch/advisories/tree/82fd27e4570433464c30b35150b197db9a850f4e/2025/SBA-ADV-20250729-01_Checkmk_Cross_Site_Scripting - () https://github.com/sbaresearch/advisories/tree/82fd27e4570433464c30b35150b197db9a850f4e/2025/SBA-ADV-20250729-01_Checkmk_Cross_Site_Scripting -

30 Oct 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-30 11:15

Updated : 2025-10-30 15:03


NVD link : CVE-2025-39663

Mitre link : CVE-2025-39663

CVE.ORG link : CVE-2025-39663


JSON object : View

Products Affected

No product.

CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)