VYPR

Vendor CVEs

Cacti (software)

All CVEs

172 total · sorted by risk
  • CVE-2023-39516MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39515MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the cacti's database. These data will be viewed by…

  • CVE-2023-39514MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39513MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39512MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39510MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39366MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39360MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework.Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data. The vulnerability is found in `graphs_new.php`. Several validations are…

  • CVE-2022-48547MedAug 22, 2023
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers to inject arbitrary web script or HTML in the "ref" parameter at auth_changepassword.php.

  • CVE-2022-41444MedAug 22, 2023
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in Cacti 1.2.21 via crafted POST request to graphs_new.php.

  • CVE-2021-26247MedJan 19, 2022
    risk 0.40cvss 6.1epss 0.07

    As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=" to successfully execute the JavaScript payload present in the "ref" URL parameter.

  • CVE-2020-23226MedAug 27, 2021
    risk 0.40cvss 6.1epss 0.02

    Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php.

  • CVE-2020-7106MedJan 16, 2020
    risk 0.40cvss 6.1epss 0.02

    Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is…

  • CVE-2017-16785MedNov 10, 2017
    risk 0.40cvss 6.1epss 0.01

    Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.

  • CVE-2017-15194MedOct 11, 2017
    risk 0.40cvss 6.1epss 0.01

    include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.

  • CVE-2017-12927MedAug 18, 2017
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.

  • CVE-2017-1000032MedJul 17, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.

  • CVE-2024-43365MedOct 7, 2024
    risk 0.39cvss 5.7epss 0.22

    Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external links in links.php . Morever, the said consolenewsection parameter is stored in the database and reflected back to user in…

  • CVE-2026-40941MedJun 25, 2026
    risk 0.35cvss 6.5epss 0.00

    Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.

  • CVE-2026-40084MedJun 25, 2026
    risk 0.35cvss 6.5epss 0.00

    Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report format_file Parameter, causing arbitrary file read. This vulnerability occurs in two stages. In the first stage (stored injection),…

  • CVE-2025-45160MedJan 29, 2026
    risk 0.35cvss 5.4epss 0.00

    A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid format is uploaded, the application reflects the submitted filename back into an error popup without proper sanitization. As a result, attackers can inject…

  • CVE-2024-29894MedMay 14, 2024
    risk 0.35cvss 5.4epss 0.01

    Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js…

  • CVE-2023-50250MedDec 22, 2023
    risk 0.35cvss 5.4epss 0.01

    Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in version 1.2.25. Attackers can exploit this vulnerability to perform actions on behalf of other users. The vulnerability is found in…

  • CVE-2022-48538MedAug 22, 2023
    risk 0.35cvss 5.3epss 0.01

    In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password.

  • CVE-2021-3816MedJan 19, 2022
    risk 0.35cvss 5.4epss 0.01

    Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a new group via "Copy" method at user_group_admin.php.

  • CVE-2021-23225MedJan 19, 2022
    risk 0.35cvss 5.4epss 0.01

    Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.

  • CVE-2019-11025MedApr 8, 2019
    risk 0.35cvss 5.4epss 0.01

    In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.

  • CVE-2018-10061MedApr 12, 2018
    risk 0.35cvss 5.4epss 0.01

    Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).

  • CVE-2018-10060MedApr 12, 2018
    risk 0.35cvss 5.4epss 0.01

    Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php.

  • CVE-2018-10059MedApr 12, 2018
    risk 0.35cvss 5.4epss 0.01

    Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAME'] to determine a page name.

  • CVE-2017-12978MedAug 21, 2017
    risk 0.35cvss 5.4epss 0.01

    lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

  • CVE-2017-12066MedAug 1, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. NOTE: this vulnerability exists…

  • CVE-2017-11691MedJul 27, 2017
    risk 0.35cvss 5.4epss 0.02

    Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.

  • CVE-2017-11163MedJul 10, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.

  • CVE-2017-10970MedJul 6, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php.

  • CVE-2026-40080MedJun 25, 2026
    risk 0.33cvss 6.1epss 0.00

    Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring check rather than a host check at str_contains($referer, CACTI_PATH_URL). When the user's login_opts == '1' (redirect to referer…

  • CVE-2026-39900MedJun 24, 2026
    risk 0.33cvss 6.1epss 0.00

    Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflected XSS via tab parameter in the auth_profile.php JavaScript context. This issue has been fixed in version 1.2.31.

  • CVE-2026-39897MedJun 24, 2026
    risk 0.33cvss 6.1epss 0.00

    Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vulnerability in the html_auth_footer. This issue has been fixed in version 1.2.31.

  • CVE-2024-30268MedMay 14, 2024
    risk 0.33cvss 6.1epss 0.01

    Cacti provides an operational monitoring and fault management framework. A reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows attackers to obtain cookies of administrator and other users and fake their login using obtained cookies. This issue is fixed in…

  • CVE-2017-16661MedNov 8, 2017
    risk 0.32cvss 4.9epss 0.01

    Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/passwd.

  • CVE-2024-31458MedMay 14, 2024
    risk 0.31cvss 4.6epss 0.13

    Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not thoroughly checked and is used to concatenate the SQL statement in…

  • CVE-2024-31444MedMay 14, 2024
    risk 0.31cvss 4.6epss 0.15

    Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the HTML statement in…

  • CVE-2023-39365MedSep 5, 2023
    risk 0.30cvss 4.6epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Issues with Cacti Regular Expression validation combined with the external links feature can lead to limited SQL Injections and subsequent data leakage. This issue has been addressed in version…

  • CVE-2026-40082MedJun 25, 2026
    risk 0.28cvss 5.4epss 0.00

    Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leading to Session Fixation. session_regenerate_id() is NOT called after successful login. The login flow at auth_login.php:203-207…

  • CVE-2023-30534MedSep 5, 2023
    risk 0.28cvss 4.3epss 0.03

    Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory (phpseclib), the necessary gadgets are not included,…

  • CVE-2020-13230MedMay 20, 2020
    risk 0.28cvss 4.3epss 0.01

    In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account (e.g., permission to view logs).

  • CVE-2019-16723MedSep 23, 2019
    risk 0.28cvss 4.3epss 0.01

    In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.

  • CVE-2026-39899MedJun 24, 2026
    risk 0.27cvss 5.3epss 0.00

    Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal via filename parameter in package_import.php. This issue has been fixed in version 1.2.31.

  • CVE-2023-39364LowSep 5, 2023
    risk 0.23cvss 3.5epss 0.01

    Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, users with console access can be redirected to an arbitrary website after a change password performed via a specifically crafted URL. The `auth_changepassword.php` file accepts `ref`…

  • CVE-2022-46169CriKEVDec 5, 2022
    risk 0.23cvss 9.8epss 1.00

    Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if…