Nagiosfusion
by Nagios
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-28906 | Hig | 0.58 | 8.8 | 0.05 | May 24, 2021 | Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included (aka sourced) by scripts executed by root. | ||
| CVE-2018-12501 | Med | 0.40 | 6.1 | 0.02 | Jun 16, 2018 | Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335. | ||
| CVE-2023-53690 | Med | 0.31 | 4.8 | 0.01 | Oct 30, 2025 | Nagios Fusion versions prior to 4.2.0 contain a stored cross-site scripting (XSS) vulnerability in the LDAP/AD authentication-server configuration. Unsanitized user input can be stored and later rendered in the administrative UI, causing JavaScript to execute in the browser of… |
- risk 0.58cvss 8.8epss 0.05
Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included (aka sourced) by scripts executed by root.
- risk 0.40cvss 6.1epss 0.02
Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335.
- risk 0.31cvss 4.8epss 0.01
Nagios Fusion versions prior to 4.2.0 contain a stored cross-site scripting (XSS) vulnerability in the LDAP/AD authentication-server configuration. Unsanitized user input can be stored and later rendered in the administrative UI, causing JavaScript to execute in the browser of…