Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3.0p39, 2.2.0 and 2.1.0 (eol).
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Checkmk Checkmk checkmk | |
| Vendors & Products | Checkmk Checkmk checkmk | 
Thu, 30 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 30 Oct 2025 10:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3.0p39, 2.2.0 and 2.1.0 (eol). | |
| Title | Cross Site Scripting through compromised remote site | |
| Weaknesses | CWE-80 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Checkmk
Published: 2025-10-30T10:43:08.500Z
Updated: 2025-10-30T13:25:58.384Z
Reserved: 2025-04-16T07:07:38.256Z
Link: CVE-2025-39663
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-30T13:25:45.664Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-10-30T11:15:32.400
Modified: 2025-10-30T15:03:13.440
Link: CVE-2025-39663
 Redhat
                        Redhat
                    No data.