XI
by Nagios
CVEs (195)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-34288 | Med | 0.44 | 6.7 | 0.02 | Dec 16, 2025 | Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑accessible maintenance script may be executed as root via sudo and includes an application file… | ||
| CVE-2018-15712 | Med | 0.44 | 6.1 | 0.49 | Nov 14, 2018 | Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php. | ||
| CVE-2023-40931 | Med | 0.43 | 6.5 | 0.11 | Sep 19, 2023 | A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php | ||
| CVE-2021-37223 | Med | 0.43 | 6.5 | 0.05 | Oct 5, 2021 | Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI application. Due to lack of input sanitisation, the… | ||
| CVE-2024-13998 | Med | 0.42 | 6.5 | 0.01 | Nov 3, 2025 | Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to… | ||
| CVE-2025-34283 | Med | 0.42 | 6.5 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user's or their own API key value. | ||
| CVE-2013-10072 | Med | 0.42 | 6.5 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints and pages that should require elevated permissions, exposing discovery results and allowing… | ||
| CVE-2024-54961 | Med | 0.42 | 6.5 | 0.02 | Feb 20, 2025 | Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users. | ||
| CVE-2024-54960 | Med | 0.42 | 6.5 | 0.01 | Feb 20, 2025 | A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component. | ||
| CVE-2022-29271 | Med | 0.42 | 6.5 | 0.02 | Jun 29, 2022 | In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks. | ||
| CVE-2022-29269 | Med | 0.42 | 6.5 | 0.03 | Jun 29, 2022 | In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address. | ||
| CVE-2021-38156 | Med | 0.42 | 5.4 | 0.89 | Sep 15, 2021 | In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard. | ||
| CVE-2021-26023 | Med | 0.42 | 6.1 | 0.25 | Feb 3, 2021 | The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS. | ||
| CVE-2020-27988 | Med | 0.42 | 5.4 | 0.91 | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field). | ||
| CVE-2020-5790 | Med | 0.42 | 6.5 | 0.02 | Oct 20, 2020 | Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link. | ||
| CVE-2020-15902 | Med | 0.42 | 6.1 | 0.35 | Jul 22, 2020 | Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option. | ||
| CVE-2019-9167 | Med | 0.41 | 6.1 | 0.22 | Mar 28, 2019 | Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter. | ||
| CVE-2024-14006 | Med | 0.40 | 6.1 | 0.00 | Oct 30, 2025 | Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote attacker can supply a crafted Host header to… | ||
| CVE-2024-13993 | Med | 0.40 | 6.1 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page when accessed with older web browsers. Insufficient validation or escaping of user-supplied input reflected by the login page can allow an attacker to craft a… | ||
| CVE-2021-47694 | Med | 0.40 | 6.1 | 0.00 | Oct 30, 2025 | The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerability via the Test Command functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject… |
- risk 0.44cvss 6.7epss 0.02
Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑accessible maintenance script may be executed as root via sudo and includes an application file…
- risk 0.44cvss 6.1epss 0.49
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.
- risk 0.43cvss 6.5epss 0.11
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php
- risk 0.43cvss 6.5epss 0.05
Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI application. Due to lack of input sanitisation, the…
- risk 0.42cvss 6.5epss 0.01
Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to…
- risk 0.42cvss 6.5epss 0.01
Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user's or their own API key value.
- risk 0.42cvss 6.5epss 0.01
Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints and pages that should require elevated permissions, exposing discovery results and allowing…
- risk 0.42cvss 6.5epss 0.02
Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users.
- risk 0.42cvss 6.5epss 0.01
A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.
- risk 0.42cvss 6.5epss 0.02
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
- risk 0.42cvss 6.5epss 0.03
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
- risk 0.42cvss 5.4epss 0.89
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.
- risk 0.42cvss 6.1epss 0.25
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.
- risk 0.42cvss 5.4epss 0.91
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
- risk 0.42cvss 6.5epss 0.02
Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
- risk 0.42cvss 6.1epss 0.35
Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.
- risk 0.41cvss 6.1epss 0.22
Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter.
- risk 0.40cvss 6.1epss 0.00
Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote attacker can supply a crafted Host header to…
- risk 0.40cvss 6.1epss 0.01
Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page when accessed with older web browsers. Insufficient validation or escaping of user-supplied input reflected by the login page can allow an attacker to craft a…
- risk 0.40cvss 6.1epss 0.00
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerability via the Test Command functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject…
Page 6 of 10