VYPR

Netbox

by Netbox Community

Source repositories

CVEs (12)

  • CVE-2023-33796CriMay 24, 2023
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, granting them access to sensitive data stored in the database. NOTE: the vendor disputes this because the reporter's only query was for the schema of the API, which…

  • CVE-2026-29514HigMay 4, 2026
    risk 0.50cvss 8.8epss 0.01

    NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary code by specifying malicious Python…

  • CVE-2024-56917HigJun 24, 2025
    risk 0.46cvss 7.1epss 0.00

    Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.

  • CVE-2024-56915MedJun 26, 2025
    risk 0.42cvss 6.5epss 0.00

    Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget.

  • CVE-2024-56916MedJun 24, 2025
    risk 0.40cvss 6.1epss 0.00

    In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) due to the `current value` field rendering user supplied html. An authenticated attacker can leverage this to add malicious JavaScript to the any banner field.…

  • CVE-2024-56918MedJun 24, 2025
    risk 0.40cvss 6.1epss 0.00

    In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authenticated attacker to exfiltrate user input from the login form.

  • CVE-2026-86175MedSep 5, 2026
    risk 0.35cvss 6.5epss 0.00

    NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining…

  • CVE-2026-69117MedAug 11, 2026
    risk 0.35cvss 6.5epss 0.00

    NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitrary Django ORM lookup expressions into nested object references by supplying crafted JSON dictionary keys in POST, PUT, or PATCH…

  • CVE-2023-37625MedAug 10, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates.

  • CVE-2019-25011MedDec 31, 2020
    risk 0.35cvss 5.4epss 0.01

    NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as demonstrated by /dcim/sites/add/ comments.

  • CVE-2025-69848MedFeb 3, 2026
    risk 0.28cvss 5.4epss 0.00

    NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object names are included in HTML error messages…

  • CVE-2026-86176MedSep 5, 2026
    risk 0.21cvss 4.3epss 0.00

    NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through unscoped querysets, disclosing which users…