VYPR

Nagiosfusion

by Nagios

CVEs (3)

  • CVE-2020-28906HigMay 24, 2021
    risk 0.58cvss 8.8epss 0.05

    Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included (aka sourced) by scripts executed by root.

  • CVE-2018-12501MedJun 16, 2018
    risk 0.40cvss 6.1epss 0.02

    Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335.

  • CVE-2023-53690MedOct 30, 2025
    risk 0.31cvss 4.8epss 0.01

    Nagios Fusion versions prior to 4.2.0 contain a stored cross-site scripting (XSS) vulnerability in the LDAP/AD authentication-server configuration. Unsanitized user input can be stored and later rendered in the administrative UI, causing JavaScript to execute in the browser of…