VYPR

Cacti

by Cacti (software)

Source repositories

CVEs (171)

  • CVE-2021-26247MedJan 19, 2022
    risk 0.40cvss 6.1epss 0.07

    As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=" to successfully execute the JavaScript payload present in the "ref" URL parameter.

  • CVE-2020-23226MedAug 27, 2021
    risk 0.40cvss 6.1epss 0.02

    Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php.

  • CVE-2020-7106MedJan 16, 2020
    risk 0.40cvss 6.1epss 0.02

    Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is…

  • CVE-2017-16785MedNov 10, 2017
    risk 0.40cvss 6.1epss 0.01

    Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.

  • CVE-2017-15194MedOct 11, 2017
    risk 0.40cvss 6.1epss 0.01

    include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.

  • CVE-2017-12927MedAug 18, 2017
    risk 0.40cvss 6.1epss 0.02

    A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.

  • CVE-2017-1000032MedJul 17, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.

  • CVE-2024-43365MedOct 7, 2024
    risk 0.39cvss 5.7epss 0.25

    Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external links in links.php . Morever, the said consolenewsection parameter is stored in the database and reflected back to user in…

  • CVE-2026-40941MedJun 25, 2026
    risk 0.35cvss 6.5epss 0.00

    Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.

  • CVE-2026-40084MedJun 25, 2026
    risk 0.35cvss 6.5epss 0.00

    Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report format_file Parameter, causing arbitrary file read. This vulnerability occurs in two stages. In the first stage (stored injection),…

  • CVE-2025-45160MedJan 29, 2026
    risk 0.35cvss 5.4epss 0.00

    A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid format is uploaded, the application reflects the submitted filename back into an error popup without proper sanitization. As a result, attackers can inject…

  • CVE-2024-29894MedMay 14, 2024
    risk 0.35cvss 5.4epss 0.01

    Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js…

  • CVE-2023-50250MedDec 22, 2023
    risk 0.35cvss 5.4epss 0.01

    Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in version 1.2.25. Attackers can exploit this vulnerability to perform actions on behalf of other users. The vulnerability is found in…

  • CVE-2022-48538MedAug 22, 2023
    risk 0.35cvss 5.3epss 0.01

    In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password.

  • CVE-2021-3816MedJan 19, 2022
    risk 0.35cvss 5.4epss 0.01

    Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a new group via "Copy" method at user_group_admin.php.

  • CVE-2021-23225MedJan 19, 2022
    risk 0.35cvss 5.4epss 0.01

    Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.

  • CVE-2019-11025MedApr 8, 2019
    risk 0.35cvss 5.4epss 0.01

    In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.

  • CVE-2018-10061MedApr 12, 2018
    risk 0.35cvss 5.4epss 0.01

    Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).

  • CVE-2018-10060MedApr 12, 2018
    risk 0.35cvss 5.4epss 0.01

    Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php.

  • CVE-2018-10059MedApr 12, 2018
    risk 0.35cvss 5.4epss 0.01

    Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAME'] to determine a page name.

Page 4 of 9