XI
by Nagios
CVEs (195)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-36862 | Med | 0.40 | 6.1 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/returned content due to insufficient output encoding (XSS), and (2) cause the server to fetch… | ||
| CVE-2013-10071 | Med | 0.40 | 6.1 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashlet AJAX load functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the… | ||
| CVE-2025-56432 | Med | 0.40 | 6.1 | 0.01 | Aug 26, 2025 | A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in user's session via a specially crafted URL. The issue resides in a web component responsible for… | ||
| CVE-2024-54957 | Med | 0.40 | 6.1 | 0.01 | Feb 27, 2025 | Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a malicious link that redirects users to an arbitrary external URL without their consent. | ||
| CVE-2024-54959 | Med | 0.40 | 6.1 | 0.01 | Feb 20, 2025 | Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS). | ||
| CVE-2024-54958 | Med | 0.40 | 6.1 | 0.01 | Feb 20, 2025 | Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page. | ||
| CVE-2020-23992 | Med | 0.40 | 6.1 | 0.02 | Aug 22, 2023 | Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request. | ||
| CVE-2022-38254 | Med | 0.40 | 6.1 | 0.02 | Sep 7, 2022 | Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5. | ||
| CVE-2022-38249 | Med | 0.40 | 6.1 | 0.02 | Sep 7, 2022 | Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4. | ||
| CVE-2022-38248 | Med | 0.40 | 6.1 | 0.02 | Sep 7, 2022 | Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php. | ||
| CVE-2022-29272 | Med | 0.40 | 6.1 | 0.04 | Jun 29, 2022 | In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing. | ||
| CVE-2021-33179 | Med | 0.40 | 6.1 | 0.12 | Oct 14, 2021 | The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload. | ||
| CVE-2021-37352 | Med | 0.40 | 6.1 | 0.06 | Aug 13, 2021 | An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link. | ||
| CVE-2018-20172 | Med | 0.40 | 6.1 | 0.02 | Dec 17, 2018 | An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability. | ||
| CVE-2018-20171 | Med | 0.40 | 6.1 | 0.02 | Dec 17, 2018 | An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability. | ||
| CVE-2018-15714 | Med | 0.40 | 6.1 | 0.04 | Nov 14, 2018 | Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters. | ||
| CVE-2020-27991 | Med | 0.37 | 5.4 | 0.34 | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field). | ||
| CVE-2020-27990 | Med | 0.37 | 5.4 | 0.34 | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent). | ||
| CVE-2020-27989 | Med | 0.37 | 5.4 | 0.34 | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard). | ||
| CVE-2020-10821 | Med | 0.37 | 4.8 | 0.71 | Mar 22, 2020 | Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter. |
- risk 0.40cvss 6.1epss 0.01
Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/returned content due to insufficient output encoding (XSS), and (2) cause the server to fetch…
- risk 0.40cvss 6.1epss 0.01
Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashlet AJAX load functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the…
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in user's session via a specially crafted URL. The issue resides in a web component responsible for…
- risk 0.40cvss 6.1epss 0.01
Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a malicious link that redirects users to an arbitrary external URL without their consent.
- risk 0.40cvss 6.1epss 0.01
Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page.
- risk 0.40cvss 6.1epss 0.02
Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request.
- risk 0.40cvss 6.1epss 0.02
Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.
- risk 0.40cvss 6.1epss 0.02
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.
- risk 0.40cvss 6.1epss 0.02
Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.
- risk 0.40cvss 6.1epss 0.04
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
- risk 0.40cvss 6.1epss 0.12
The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload.
- risk 0.40cvss 6.1epss 0.06
An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability.
- risk 0.40cvss 6.1epss 0.04
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.
- risk 0.37cvss 5.4epss 0.34
Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).
- risk 0.37cvss 5.4epss 0.34
Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).
- risk 0.37cvss 5.4epss 0.34
Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).
- risk 0.37cvss 4.8epss 0.71
Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.
Page 7 of 10