CVE-2025-27240
12.09.2025, 11:15
A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
| Vendor | Product | Version |
|---|---|---|
| zabbix | zabbix | 6.0.0 ≤ 𝑥 < 6.0.34 |
| zabbix | zabbix | 6.4.0 ≤ 𝑥 < 6.4.19 |
| zabbix | zabbix | 7.0.0 ≤ 𝑥 < 7.0.4 |
𝑥
= Vulnerable software versions
Debian Releases