VYPR

Nagios XI

by Nagios

CVEs (4)

  • CVE-2026-48554HigAug 12, 2026
    risk 0.49cvss 7.5epss

    Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command references $NOTIFICATIONCOMMENT$ or…

  • CVE-2026-48551HigAug 12, 2026
    risk 0.48cvss 7.4epss

    Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, enabling unauthenticated…

  • CVE-2026-48550MedAug 12, 2026
    risk 0.40cvss 6.1epss

    Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by an authenticated user, executes arbitrary…

  • CVE-2026-48552MedAug 12, 2026
    risk 0.35cvss 5.4epss

    Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization, allowing attackers to run arbitrary JavaScript in…