VYPR

Nagios

by Nagios

Source repositories

CVEs (181)

  • CVE-2020-36861MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.8 / Nagios XI 5.7.5 contains multiple cross-site scripting (XSS) vulnerabilities in the overlay UI elements and the Notification/Check Period pages. Insufficient validation or escaping of user-supplied input…

  • CVE-2020-36860MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple cross-site scripting (XSS) vulnerabilities in the object edit pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute…

  • CVE-2018-25121MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios XI versions prior to 5.4.13 are vulnerable to cross-site scripting (XSS) via the Views page of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

  • CVE-2016-15053MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the “My Reports” listing of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a…

  • CVE-2011-10040MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the link-handling functions used by status and report pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the…

  • CVE-2011-10039MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the Alert Heatmap report and the “My Reports” listing of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute…

  • CVE-2011-10038MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the recurring downtime script of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of…

  • CVE-2011-10037MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.01

    Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of xiwindow variables used to build permalinks in the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute…

  • CVE-2024-42898MedJan 9, 2025
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.

  • CVE-2023-40932MedSep 19, 2023
    risk 0.35cvss 5.4epss 0.01

    A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the…

  • CVE-2021-37351MedAug 13, 2021
    risk 0.35cvss 5.3epss 0.03

    Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP request to the server.

  • CVE-2018-18245MedDec 17, 2018
    risk 0.35cvss 5.4epss 0.03

    Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.

  • CVE-2018-10554MedApr 30, 2018
    risk 0.35cvss 5.4epss 0.03

    An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm parameter, related to components/scheduledreporting; (2) includes/components/xicore/downtime.php, related to the update_pages…

  • CVE-2020-10820MedMar 22, 2020
    risk 0.34cvss 4.8epss 0.19

    Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter.

  • CVE-2020-13977MedJun 9, 2020
    risk 0.32cvss 4.9epss 0.03

    Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files. NOTE: this…

  • CVE-2022-38251MedSep 7, 2022
    risk 0.31cvss 4.8epss 0.02

    Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel.

  • CVE-2022-38247MedSep 7, 2022
    risk 0.31cvss 4.8epss 0.02

    Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel.

  • CVE-2025-34135MedOct 30, 2025
    risk 0.29cvss 4.4epss 0.00

    Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. In particular, the nagios.service unit had executable permissions that were not required. Overly permissive permissions on service unit files can broaden…

  • CVE-2023-24034LowSep 14, 2026
    risk 0.20cvss 3.1epss 0.01

    An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability.

  • CVE-2009-2288Jul 1, 2009
    risk 0.10cvss —epss 0.83

    statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters.

Page 8 of 10