VYPR

Log Server

by Nagios

CVEs (26)

  • CVE-2020-16157MedJul 30, 2020
    risk 0.36cvss 5.4epss 0.14

    A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.

  • CVE-2023-7323MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios Log Server versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Create User function. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

  • CVE-2023-7321MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios Log Server versions prior to 2.1.14 are vulnerable to cross-site scripting (XSS) via the Snapshots Page. Untrusted log content was not safely encoded for the output context, allowing attacker-controlled data present in logs to execute script in the victim’s browser…

  • CVE-2020-36858MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) vulnerabilities via the web interface on the Create User, Edit User, and Manage Host Lists pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute…

  • CVE-2016-15049MedOct 30, 2025
    risk 0.35cvss 5.4epss 0.00

    Nagios Log Server versions prior to 1.4.2 are vulnerable to cross-site scripting (XSS) in the Dashboards section when rendering log entries in the Logs table. Untrusted log content was not safely encoded for the output context, allowing attacker-controlled data present in logs…

  • CVE-2025-34270MedOct 30, 2025
    risk 0.32cvss 4.9epss 0.01

    Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a result, the plaintext password supplied for imported accounts may be exposed in the user interface,…

Page 2 of 2