CVE-2024-13722: Checkmk Nagvis
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.
Affected products
- Checkmk Nagvis
Published 2025-02-04. Last modified 2026-06-17.