Medium severity5.4OSV Advisory· Published Jan 16, 2019· Updated Jun 17, 2026
CVE-2018-20726
CVE-2018-20726
Description
A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- osv-coords7 versionspkg:rpm/opensuse/cacti&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/cacti&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/cacti-spine&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2012pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2012
< 1.2.18-1.2+ 6 more
- (no CPE)range: < 1.2.18-1.2
- (no CPE)range: < 1.2.9-lp151.3.3.1
- (no CPE)range: < 1.2.9-lp151.3.3.1
- (no CPE)range: < 1.2.9-bp151.4.3.1
- (no CPE)range: < 1.2.9-bp151.4.3.1
- (no CPE)range: < 1.2.11-5.1
- (no CPE)range: < 1.2.11-2.1
<1.2.0+ 2 more
- (no CPE)range: <1.2.0
- (no CPE)range: release/1.0.0, release/1.0.1, release/1.0.2, …
- cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*range: <1.2.0
Patches
Vulnerability mechanics
References
7- github.com/Cacti/cacti/commit/80c2a88fb2afb93f87703ba4641f9970478c102dnvdPatchThird Party Advisory
- github.com/Cacti/cacti/issues/2213nvdExploitIssue TrackingThird Party Advisory
- github.com/Cacti/cacti/blob/develop/CHANGELOGnvdRelease NotesThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.htmlnvd
News mentions
0No linked articles in our index yet.