VYPR
Vendor

Netbox Community

Products
3
CVEs
12
Across products
16
Status
Private

Products

3

Recent CVEs

12
  • CVE-2023-27573CriMar 11, 2026
    risk 0.59cvss 9.0epss 0.00

    netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SUPERUSER_API_TOKEN). In practice on the public Internet, almost all users changed the password but only…

  • CVE-2023-33796CriMay 24, 2023
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, granting them access to sensitive data stored in the database. NOTE: the vendor disputes this because the reporter's only query was for the schema of the API, which…

  • CVE-2022-22986HigMar 31, 2022
    risk 0.57cvss 8.8epss 0.01

    Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier) allow an attacker on the adjacent network to execute an arbitrary OS command via a specially crafted config file.

  • CVE-2026-29514HigMay 4, 2026
    risk 0.50cvss 8.8epss 0.01

    NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary code by specifying malicious Python…

  • CVE-2024-56917HigJun 24, 2025
    risk 0.46cvss 7.1epss 0.00

    Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.

  • CVE-2024-56915MedJun 26, 2025
    risk 0.42cvss 6.5epss 0.00

    Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget.

  • CVE-2024-56916MedJun 24, 2025
    risk 0.40cvss 6.1epss 0.00

    In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) due to the `current value` field rendering user supplied html. An authenticated attacker can leverage this to add malicious JavaScript to the any banner field.…

  • CVE-2024-56918MedJun 24, 2025
    risk 0.40cvss 6.1epss 0.00

    In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authenticated attacker to exfiltrate user input from the login form.

  • CVE-2026-69117MedAug 11, 2026
    risk 0.35cvss 6.5epss 0.00

    NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitrary Django ORM lookup expressions into nested object references by supplying crafted JSON dictionary keys in POST, PUT, or PATCH…

  • CVE-2025-69848MedFeb 3, 2026
    risk 0.35cvss 5.4epss 0.00

    NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object names are included in HTML error messages…

  • CVE-2023-37625MedAug 10, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates.

  • CVE-2019-25011MedDec 31, 2020
    risk 0.35cvss 5.4epss 0.01

    NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as demonstrated by /dcim/sites/add/ comments.

VYPR — Vulnerability Intelligence