VYPR

Cacti

by Cacti (software)

Source repositories

CVEs (171)

  • CVE-2024-54145MedJan 27, 2025
    risk 0.00cvss 6.3epss 0.01

    Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the get_discovery_results function of automation_devices.php using the network parameter. This vulnerability is fixed in 1.2.29.

  • CVE-2024-45598MedJan 27, 2025
    risk 0.00cvss 6.0epss 0.03

    Cacti is an open source performance and fault management framework. Prior to 1.2.29, an administrator can change the `Poller Standard Error Log Path` parameter in either Installation Step 5 or in Configuration->Settings->Paths tab to a local file inside the server. Then simply…

  • CVE-2024-31443MedMay 14, 2024
    risk 0.00cvss 5.7epss 0.01

    Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_pane_tree()` function from…

  • CVE-2023-49086MedDec 22, 2023
    risk 0.00cvss 5.4epss 0.01

    Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). A vulnerability in versions prior to 1.2.27 bypasses an earlier fix for CVE-2023-39360, therefore leading to a DOM XSS attack. Exploitation of the…

  • CVE-2020-14424MedNov 14, 2021
    risk 0.00cvss 6.1epss 0.02

    Cacti before 1.2.18 allows remote attackers to trigger XSS via template import for the midwinter theme.

  • CVE-2020-25706MedNov 12, 2020
    risk 0.00cvss 5.4epss 0.03

    A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field

  • CVE-2018-20726MedJan 16, 2019
    risk 0.00cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.

  • CVE-2018-20725MedJan 16, 2019
    risk 0.00cvss 4.8epss 0.01

    A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Graph Vertical Label.

  • CVE-2018-20724MedJan 16, 2019
    risk 0.00cvss 4.8epss 0.01

    A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname for Data Collectors.

  • CVE-2018-20723MedJan 16, 2019
    risk 0.00cvss 4.8epss 0.01

    A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.

  • CVE-2015-8369Dec 17, 2015
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a properties action to graph.php.

  • CVE-2015-8377Dec 15, 2015
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted serialized data in the selected_graphs_array parameter in a save action.

  • CVE-2015-4634Aug 11, 2015
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.

  • CVE-2015-2967Jul 10, 2015
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in settings.php in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-4454Jun 17, 2015
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.

  • CVE-2015-4342Jun 17, 2015
    risk 0.00cvss —epss 0.03

    SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving a cdef id.

  • CVE-2015-2665Jun 17, 2015
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-0916May 22, 2015
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.

  • CVE-2014-5026Oct 20, 2014
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (3) CDEF Name, (4) Data Input Method Name, or (5) Host…

  • CVE-2014-5025Oct 20, 2014
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action.

Page 7 of 9