Aggregates CVE and security vulnerability intelligence across all it-novum-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk cross-site scripting, vendor risk ssrf, and vendor risk sql injection and related problems; some flaws may lead to vendor impact session compromise and vendor impact data exposure.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2026-24892 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization pattern in the processing of changelog entries. Serialized changelog data derived from attacker-influenced application state is unserialized without restricting allowed classes. Although no current application endpoint was found to introduce PHP objects into this data path, the presence | [email protected] | 7.5 | 0.28% | 2026-02-20 | 2026-03-02 |
| CVE-2026-24891 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearman worker implementation. The worker function registered as oitc_gearman calls PHP's unserialize() on job payloads without enforcing class restrictions or validating data origin. While the intended deployment assumes only trusted internal components enqueue Gearman jobs, this trust boundary is not en | [email protected] | 7.5 | 0.15% | 2026-02-20 | 2026-02-24 |
| CVE-2023-3520 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6. | [email protected] | 4.6 | 0.03% | 2023-07-06 | 2024-11-21 |
| CVE-2023-36663 | it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface. | [email protected] | 8.8 | 0.41% | 2023-06-25 | 2024-11-21 |
| CVE-2023-3218 | Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5. | [email protected] | 4.4 | 0.03% | 2023-06-13 | 2024-11-21 |
| CVE-2020-10788 | openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections. | [email protected] | 9.1 | 0.26% | 2020-03-25 | 2024-11-21 |
| CVE-2020-10791 | app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module. | [email protected] | 6.5 | 0.14% | 2020-03-25 | 2024-11-21 |
| CVE-2020-10790 | openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS. | [email protected] | 5.4 | 0.38% | 2020-03-25 | 2024-11-21 |
| CVE-2020-10789 | openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php. | [email protected] | 9.8 | 0.59% | 2020-03-25 | 2024-11-21 |
| CVE-2020-10792 | openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header. | [email protected] | 7.5 | 0.46% | 2020-03-20 | 2024-11-21 |
| CVE-2019-10227 | openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component. | [email protected] | 6.1 | 0.43% | 2019-12-31 | 2024-11-21 |
| CVE-2019-15494 | openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21. | [email protected] | 9.8 | 0.36% | 2019-08-23 | 2024-11-21 |
| CVE-2019-15493 | openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21. | [email protected] | 7.5 | 0.24% | 2019-08-23 | 2024-11-21 |
| CVE-2019-15492 | openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21. | [email protected] | 6.1 | 0.24% | 2019-08-23 | 2024-11-21 |
| CVE-2019-15491 | openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21. | [email protected] | 8.8 | 0.07% | 2019-08-23 | 2024-11-21 |
| CVE-2019-15490 | openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21. | [email protected] | 9.8 | 0.51% | 2019-08-23 | 2024-11-21 |