CVE-2025-39663

Publication date

2025-10-30 10:43:08

Family

Checkmk

State

PUBLISHED

Description

Cross-Site Scripting (XSS) vulnerability in Checkmks distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3.0p39, 2.2.0 and 2.1.0 (eol).