CVE-2025-4650: Centreon Web

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutralization of Special Elements used in an SQL Command.This issue affects web: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before 23.10.26.

Affected products

  • Centreon Centreon Web: from 23.10.0, before 23.10.26 (fixed in 23.10.26); from 24.04.0, before 24.04.16 (fixed in 24.04.16); from 24.10.0, before 24.10.9 (fixed in 24.10.9)

Published 2025-08-22. Last modified 2026-06-17.