Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-20915

Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will execute in the browsers of other users viewing the sidebar.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.0%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2026-20915
  • Checkmk » Checkmk » Version: 2.5.0
    cpe:2.3:a:checkmk:checkmk:2.5.0


Contact Us

Shodan ® - All rights reserved