CVE-2023-32721 HIGH

CVE-2023-32721: Stored XSS in Maps element

Vendor Zabbix
Product Zabbix
Weakness CWE-20 · Input validation
Published October 12, 2023
Last update November 3, 2025

CVSS base score

7.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N

What the vulnerability does

01Description

A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.

Key dates

02Disclosure timeline

October 12, 2023 CVE published
November 3, 2025 Record updated