VYPR

XI

by Nagios

CVEs (195)

  • CVE-2020-10819MedMar 22, 2020
    risk 0.37cvss 4.8epss 0.71

    Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter.

  • CVE-2019-20139MedDec 30, 2019
    risk 0.37cvss 5.4epss 0.26

    In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin user.

  • CVE-2024-14002MedOct 30, 2025
    risk 0.36cvss 5.5epss 0.01

    Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An authenticated user can supply crafted path values that cause the server to include local files, potentially exposing sensitive information from the…

  • CVE-2021-26024MedFeb 3, 2021
    risk 0.36cvss 5.3epss 0.19

    The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.

  • CVE-2018-15713MedNov 14, 2018
    risk 0.36cvss 5.4epss 0.07

    Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php.

  • CVE-2021-47698MedNov 3, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling (escape_string()). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary…

  • CVE-2024-13992MedOct 31, 2025
    risk 0.35cvss 5.4epss 0.01

    Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link from another website. The vulnerable component, page-missing.php, fails to properly validate or escape user-supplied…

  • CVE-2024-14001MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.01

    Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Executive Summary Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's…

  • CVE-2024-14000MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.01

    Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity Planning Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's…

  • CVE-2023-7318MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.01

    Nagios XI versions prior to < 2024R1.0.2 are vulnerable to cross-site scripting (XSS) via the Nagios Core Command Expansion page. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's…

  • CVE-2023-7316MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.01

    Nagios XI versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Graph Explorer component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

  • CVE-2023-7315MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Graph Explorer component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

  • CVE-2023-7314MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

  • CVE-2023-7313MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modifications tool. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

  • CVE-2023-53688MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) and cross-site request forgery (CSRF) via the Hypermap Replay component. An attacker can submit crafted input that is not properly validated or escaped, allowing injection of malicious script that…

  • CVE-2022-50588MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the update checking feature. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

  • CVE-2022-50587MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) via the Apply Configuration error text. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

  • CVE-2022-50586MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the BPI component via the info URL field. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's…

  • CVE-2022-50585MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.7 / Nagios XI 5.8.9 contains a cross-site scripting (XSS) vulnerability via the Audit Log page search input. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and…

  • CVE-2022-50584MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.6 / Nagios XI 5.8.8 contains a cross-site scripting (XSS) vulnerability via the search and deletion interfaces. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and…

Page 8 of 10