VYPR

Cacti

by Cacti (software)

Source repositories

CVEs (171)

  • CVE-2019-17358HigDec 12, 2019
    risk 0.46cvss 8.1epss 0.03

    Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory…

  • CVE-2019-17357MedJan 21, 2020
    risk 0.45cvss 6.5epss 0.35

    Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string and id composite value are used to identify the template type and id. An authenticated attacker can exploit this to extract data…

  • CVE-2026-39951HigJun 25, 2026
    risk 0.42cvss 7.6epss 0.00

    Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graph_name_regexp in the Reports feature. This issue has been fixed in version 1.2.31.

  • CVE-2024-31460MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.02

    Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_nodes()` function from…

  • CVE-2023-46490MedOct 27, 2023
    risk 0.42cvss 6.5epss 0.01

    SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers.php function.

  • CVE-2020-13231MedMay 20, 2020
    risk 0.42cvss 6.5epss 0.01

    In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change.

  • CVE-2026-40083HigJun 25, 2026
    risk 0.40cvss 7.2epss 0.00

    Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+implode in managers.php. At line 756 of managers.php, the application assigns $selected_items by calling…

  • CVE-2024-43364MedOct 7, 2024
    risk 0.40cvss 5.7epss 0.34

    Cacti is an open source performance and fault management framework. The `title` parameter is not properly sanitized when saving external links in links.php . Morever, the said title parameter is stored in the database and reflected back to user in index.php, finally leading to…

  • CVE-2023-49088MedDec 22, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. The fix applied for CVE-2023-39515 in version 1.2.25 is incomplete as it enables an adversary to have a victim browser execute malicious code when a victim user hovers their mouse over the malicious…

  • CVE-2023-39511MedSep 6, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39516MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39515MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the cacti's database. These data will be viewed by…

  • CVE-2023-39514MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39513MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39512MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39510MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39366MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39360MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework.Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data. The vulnerability is found in `graphs_new.php`. Several validations are…

  • CVE-2022-48547MedAug 22, 2023
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers to inject arbitrary web script or HTML in the "ref" parameter at auth_changepassword.php.

  • CVE-2022-41444MedAug 22, 2023
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in Cacti 1.2.21 via crafted POST request to graphs_new.php.

Page 3 of 9