Cacti
Source repositories
CVEs (171)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-26247 | Med | 0.40 | 6.1 | 0.07 | Jan 19, 2022 | As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=" to successfully execute the JavaScript payload present in the "ref" URL parameter. | ||
| CVE-2020-23226 | Med | 0.40 | 6.1 | 0.02 | Aug 27, 2021 | Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php. | ||
| CVE-2020-7106 | Med | 0.40 | 6.1 | 0.02 | Jan 16, 2020 | Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is… | ||
| CVE-2017-16785 | Med | 0.40 | 6.1 | 0.01 | Nov 10, 2017 | Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php. | ||
| CVE-2017-15194 | Med | 0.40 | 6.1 | 0.01 | Oct 11, 2017 | include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page. | ||
| CVE-2017-12927 | Med | 0.40 | 6.1 | 0.02 | Aug 18, 2017 | A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php. | ||
| CVE-2017-1000032 | Med | 0.40 | 6.1 | 0.01 | Jul 17, 2017 | Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php. | ||
| CVE-2024-43365 | Med | 0.39 | 5.7 | 0.25 | Oct 7, 2024 | Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external links in links.php . Morever, the said consolenewsection parameter is stored in the database and reflected back to user in… | ||
| CVE-2026-40941 | Med | 0.35 | 6.5 | 0.00 | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31. | ||
| CVE-2026-40084 | Med | 0.35 | 6.5 | 0.00 | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report format_file Parameter, causing arbitrary file read. This vulnerability occurs in two stages. In the first stage (stored injection),… | ||
| CVE-2025-45160 | Med | 0.35 | 5.4 | 0.00 | Jan 29, 2026 | A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid format is uploaded, the application reflects the submitted filename back into an error popup without proper sanitization. As a result, attackers can inject… | ||
| CVE-2024-29894 | Med | 0.35 | 5.4 | 0.01 | May 14, 2024 | Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js… | ||
| CVE-2023-50250 | Med | 0.35 | 5.4 | 0.01 | Dec 22, 2023 | Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in version 1.2.25. Attackers can exploit this vulnerability to perform actions on behalf of other users. The vulnerability is found in… | ||
| CVE-2022-48538 | Med | 0.35 | 5.3 | 0.01 | Aug 22, 2023 | In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password. | ||
| CVE-2021-3816 | Med | 0.35 | 5.4 | 0.01 | Jan 19, 2022 | Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a new group via "Copy" method at user_group_admin.php. | ||
| CVE-2021-23225 | Med | 0.35 | 5.4 | 0.01 | Jan 19, 2022 | Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php. | ||
| CVE-2019-11025 | Med | 0.35 | 5.4 | 0.01 | Apr 8, 2019 | In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS. | ||
| CVE-2018-10061 | Med | 0.35 | 5.4 | 0.01 | Apr 12, 2018 | Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used). | ||
| CVE-2018-10060 | Med | 0.35 | 5.4 | 0.01 | Apr 12, 2018 | Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php. | ||
| CVE-2018-10059 | Med | 0.35 | 5.4 | 0.01 | Apr 12, 2018 | Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAME'] to determine a page name. |
- risk 0.40cvss 6.1epss 0.07
As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=" to successfully execute the JavaScript payload present in the "ref" URL parameter.
- risk 0.40cvss 6.1epss 0.02
Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php.
- risk 0.40cvss 6.1epss 0.02
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is…
- risk 0.40cvss 6.1epss 0.01
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
- risk 0.40cvss 6.1epss 0.01
include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.
- risk 0.40cvss 6.1epss 0.02
A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.
- risk 0.40cvss 6.1epss 0.01
Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.
- risk 0.39cvss 5.7epss 0.25
Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external links in links.php . Morever, the said consolenewsection parameter is stored in the database and reflected back to user in…
- risk 0.35cvss 6.5epss 0.00
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.
- risk 0.35cvss 6.5epss 0.00
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report format_file Parameter, causing arbitrary file read. This vulnerability occurs in two stages. In the first stage (stored injection),…
- risk 0.35cvss 5.4epss 0.00
A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid format is uploaded, the application reflects the submitted filename back into an error popup without proper sanitization. As a result, attackers can inject…
- risk 0.35cvss 5.4epss 0.01
Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js…
- risk 0.35cvss 5.4epss 0.01
Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in version 1.2.25. Attackers can exploit this vulnerability to perform actions on behalf of other users. The vulnerability is found in…
- risk 0.35cvss 5.3epss 0.01
In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password.
- risk 0.35cvss 5.4epss 0.01
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a new group via "Copy" method at user_group_admin.php.
- risk 0.35cvss 5.4epss 0.01
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.
- risk 0.35cvss 5.4epss 0.01
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.
- risk 0.35cvss 5.4epss 0.01
Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).
- risk 0.35cvss 5.4epss 0.01
Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php.
- risk 0.35cvss 5.4epss 0.01
Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAME'] to determine a page name.
Page 4 of 9