VYPR

XI

by Nagios

CVEs (195)

  • CVE-2020-36862MedOct 30, 2025
    risk 0.40cvss 6.1epss 0.01

    Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/returned content due to insufficient output encoding (XSS), and (2) cause the server to fetch…

  • CVE-2013-10071MedOct 30, 2025
    risk 0.40cvss 6.1epss 0.01

    Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashlet AJAX load functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the…

  • CVE-2025-56432MedAug 26, 2025
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in user's session via a specially crafted URL. The issue resides in a web component responsible for…

  • CVE-2024-54957MedFeb 27, 2025
    risk 0.40cvss 6.1epss 0.01

    Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a malicious link that redirects users to an arbitrary external URL without their consent.

  • CVE-2024-54959MedFeb 20, 2025
    risk 0.40cvss 6.1epss 0.01

    Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).

  • CVE-2024-54958MedFeb 20, 2025
    risk 0.40cvss 6.1epss 0.01

    Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page.

  • CVE-2020-23992MedAug 22, 2023
    risk 0.40cvss 6.1epss 0.02

    Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request.

  • CVE-2022-38254MedSep 7, 2022
    risk 0.40cvss 6.1epss 0.02

    Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.

  • CVE-2022-38249MedSep 7, 2022
    risk 0.40cvss 6.1epss 0.02

    Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.

  • CVE-2022-38248MedSep 7, 2022
    risk 0.40cvss 6.1epss 0.02

    Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.

  • CVE-2022-29272MedJun 29, 2022
    risk 0.40cvss 6.1epss 0.04

    In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.

  • CVE-2021-33179MedOct 14, 2021
    risk 0.40cvss 6.1epss 0.12

    The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload.

  • CVE-2021-37352MedAug 13, 2021
    risk 0.40cvss 6.1epss 0.06

    An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.

  • CVE-2018-20172MedDec 17, 2018
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability.

  • CVE-2018-20171MedDec 17, 2018
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability.

  • CVE-2018-15714MedNov 14, 2018
    risk 0.40cvss 6.1epss 0.04

    Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.

  • CVE-2020-27991MedNov 16, 2020
    risk 0.37cvss 5.4epss 0.34

    Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).

  • CVE-2020-27990MedNov 16, 2020
    risk 0.37cvss 5.4epss 0.34

    Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).

  • CVE-2020-27989MedNov 16, 2020
    risk 0.37cvss 5.4epss 0.34

    Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).

  • CVE-2020-10821MedMar 22, 2020
    risk 0.37cvss 4.8epss 0.71

    Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.

Page 7 of 10