XI
by Nagios
CVEs (195)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2011-10037 | Med | 0.35 | 5.4 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of xiwindow variables used to build permalinks in the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute… | ||
| CVE-2011-10036 | Med | 0.35 | 5.4 | 0.00 | Oct 30, 2025 | Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of the "backend_url" JavaScript link. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a… | ||
| CVE-2024-42898 | Med | 0.35 | 5.4 | 0.01 | Jan 9, 2025 | A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page. | ||
| CVE-2023-51072 | Med | 0.35 | 5.4 | 0.01 | Feb 2, 2024 | A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious HTML or JavaScript code via the audio file upload functionality from the Operation Center section. This allows… | ||
| CVE-2023-40932 | Med | 0.35 | 5.4 | 0.01 | Sep 19, 2023 | A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the… | ||
| CVE-2021-37351 | Med | 0.35 | 5.3 | 0.03 | Aug 13, 2021 | Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP request to the server. | ||
| CVE-2018-17146 | Med | 0.35 | 5.4 | 0.04 | Jun 19, 2019 | A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin management page. | ||
| CVE-2018-10554 | Med | 0.35 | 5.4 | 0.03 | Apr 30, 2018 | An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm parameter, related to components/scheduledreporting; (2) includes/components/xicore/downtime.php, related to the update_pages… | ||
| CVE-2020-10820 | Med | 0.34 | 4.8 | 0.19 | Mar 22, 2020 | Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter. | ||
| CVE-2022-38251 | Med | 0.31 | 4.8 | 0.02 | Sep 7, 2022 | Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel. | ||
| CVE-2022-38247 | Med | 0.31 | 4.8 | 0.02 | Sep 7, 2022 | Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel. | ||
| CVE-2018-17147 | Med | 0.31 | 4.8 | 0.03 | Jul 10, 2019 | Nagios XI before 5.5.4 has XSS in the auto login admin management page. | ||
| CVE-2025-34135 | Med | 0.29 | 4.4 | 0.00 | Oct 30, 2025 | Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. In particular, the nagios.service unit had executable permissions that were not required. Overly permissive permissions on service unit files can broaden… | ||
| CVE-2022-29270 | Med | 0.28 | 4.3 | 0.02 | Jun 29, 2022 | In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address. | ||
| CVE-2013-6875 | 0.03 | — | 0.03 | Nov 26, 2013 | SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php. |
- risk 0.35cvss 5.4epss 0.01
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of xiwindow variables used to build permalinks in the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute…
- risk 0.35cvss 5.4epss 0.00
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of the "backend_url" JavaScript link. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a…
- risk 0.35cvss 5.4epss 0.01
A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.
- risk 0.35cvss 5.4epss 0.01
A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious HTML or JavaScript code via the audio file upload functionality from the Operation Center section. This allows…
- risk 0.35cvss 5.4epss 0.01
A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the…
- risk 0.35cvss 5.3epss 0.03
Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP request to the server.
- risk 0.35cvss 5.4epss 0.04
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin management page.
- risk 0.35cvss 5.4epss 0.03
An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm parameter, related to components/scheduledreporting; (2) includes/components/xicore/downtime.php, related to the update_pages…
- risk 0.34cvss 4.8epss 0.19
Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter.
- risk 0.31cvss 4.8epss 0.02
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel.
- risk 0.31cvss 4.8epss 0.02
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel.
- risk 0.31cvss 4.8epss 0.03
Nagios XI before 5.5.4 has XSS in the auto login admin management page.
- risk 0.29cvss 4.4epss 0.00
Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. In particular, the nagios.service unit had executable permissions that were not required. Overly permissive permissions on service unit files can broaden…
- risk 0.28cvss 4.3epss 0.02
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
- CVE-2013-6875Nov 26, 2013risk 0.03cvss —epss 0.03
SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.
Page 10 of 10