cbcvebase.

Debian Cacti vulnerabilities

155 known vulnerabilities affecting debian/cacti.

Total CVEs
155
CISA KEV
1
actively exploited
Public exploits
25
Exploited in wild
3
Severity breakdown
CRITICAL10HIGH50MEDIUM72LOW23

Vulnerabilities

Page 1 of 8
CVE-2022-46169P1CRITICALCVSS 9.8KEVPoCfixed in cacti 1.2.22+ds1-3 (bookworm)2022
CVE-2022-46169 [CRITICAL] CVE-2022-46169: cacti - Cacti is an open source platform which provides a robust and extensible operatio... Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. The vulnerability resides
debian
CVE-2023-39361P1CRITICALCVSS 9.8ExploitedPoCfixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39361 [CRITICAL] CVE-2023-39361: cacti - Cacti is an open source operational monitoring and fault management framework. A... Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit
debian
CVE-2020-8813P1HIGHCVSS 8.8ExploitedPoCfixed in cacti 1.2.10+ds1-1 (bookworm)2020
CVE-2020-8813 [HIGH] CVE-2020-8813: cacti - graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary O... graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege. Scope: local bookworm: resolved (fixed in 1.2.10+ds1-1) bullseye: resolved (fixed in 1.2.10+ds1-1) forky: resolved (fixed in 1.2.10+ds1-1) sid: resolved (fixed in 1.2.10+ds1-1) trixie: resolve
debian
CVE-2023-49085P1HIGHCVSS 8.8PoCfixed in cacti 1.2.24+ds1-1+deb12u2 (bookworm)2023
CVE-2023-49085 [HIGH] CVE-2023-49085: cacti - Cacti provides an operational monitoring and fault management framework. In vers... Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script. An authorized user may be able to execute arbitrary SQL code. The vulnerable component is the `pollers.php`. Impact of the vulnerability - arbitrary SQL code execution. As of time of publi
debian
CVE-2023-49084P2HIGHCVSS 8.0PoCfixed in cacti 1.2.24+ds1-1+deb12u2 (bookworm)2023
CVE-2023-49084 [HIGH] CVE-2023-49084: cacti - Cacti is a robust performance and fault management framework and a frontend to R... Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient processing of the include file path, it is possible to execute arbitrary code on the server. Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is the
debian
CVE-2025-24367P1HIGHCVSS 8.7PoCfixed in cacti 1.2.24+ds1-1+deb12u5 (bookworm)2025
CVE-2025-24367 [HIGH] CVE-2025-24367: cacti - Cacti is an open source performance and fault management framework. An authentic... Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29. Scope: local bookworm: resolved (fixed in 1.2.24+ds1-1+deb12u
debian
CVE-2024-25641P2CRITICALCVSS 9.1PoCfixed in cacti 1.2.24+ds1-1+deb12u3 (bookworm)2024
CVE-2024-25641 [CRITICAL] CVE-2024-25641: cacti - Cacti provides an operational monitoring and fault management framework. Prior t... Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server. The vulnerability is located within the `import_package()` fun
debian
CVE-2023-39362P2HIGHCVSS 7.2PoCfixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39362 [HIGH] CVE-2023-39362: cacti - Cacti is an open source operational monitoring and fault management framework. I... Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server. The `lib/snmp.php` file has a set of functions, with similar be
debian
CVE-2020-14295P2HIGHCVSS 7.2PoCfixed in cacti 1.2.13+ds1-1 (bookworm)2020
CVE-2020-14295 [HIGH] CVE-2020-14295: cacti - A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL... A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries. Scope: local bookworm: resolved (fixed in 1.2.13+ds1-1) bullseye: resolved (fixed in 1.2.13+ds1-1) forky: resolved (fixed in 1.2.13+ds1-1) sid: resolved (fixed in 1.2.13+ds1-1)
debian
CVE-2005-10004P2HIGHCVSS 8.7PoCfixed in cacti 0.8.6d-1 (bookworm)2005
CVE-2005-10004 [HIGH] CVE-2005-10004: cacti - Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability... Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web s
debian
CVE-2009-4112P3LOWCVSS 9.0PoCfixed in cacti 1.2.1+ds1-1 (bookworm)2009
CVE-2009-4112 [CRITICAL] CVE-2009-4112: cacti - Cacti 0.8.7e and earlier allows remote authenticated administrators to gain priv... Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memory Usage" setting to contain arbitrary commands. Scope: local bookworm: resolved (fixed in 1.2.1+ds1-1) bullseye: resolved (fixed in 1.2.1+ds1-1) forky: resolved (fixed in 1.2.1+ds1-1) sid: resolved (fixed in 1.2.1+ds1-
debian
CVE-2023-51448P2LOWCVSS 8.8fixed in cacti 1.2.26+ds1-1 (forky)2023
CVE-2023-51448 [HIGH] CVE-2023-51448: cacti - Cacti provides an operational monitoring and fault management framework. Version... Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNMP Notification Receivers feature in the file `‘managers.php’`. An authenticated attacker with the “Settings/Utilities” permission can send a crafted HTTP GET request to the endpoint `‘/cacti/managers.php’` with an SQLi pa
debian
CVE-2020-7237P2HIGHCVSS 8.8fixed in cacti 1.2.9+ds1-1 (bookworm)2020
CVE-2020-7237 [HIGH] CVE-2020-7237: cacti - Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacha... Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller cycle begins. The attacker must be authenticated, and must have access to modify the Performance Settings of the product. Scope: local bookworm: resolved (fixed in 1.2.9+ds1-
debian
CVE-2006-0146P3MEDIUMCVSS 7.5PoCfixed in cacti 0.8.6d-1 (bookworm)2006
CVE-2006-0146 [HIGH] CVE-2006-0146: cacti - The server.php test script in ADOdb for PHP before 4.70, as used in multiple pro... The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter. Scope: local bookworm: resolved (fixed i
debian
CVE-2024-31445P2HIGHCVSS 8.8fixed in cacti 1.2.24+ds1-1+deb12u3 (bookworm)2024
CVE-2024-31445 [HIGH] CVE-2024-31445: cacti - Cacti provides an operational monitoring and fault management framework. Prior t... Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_new_graphs_sql` function of `api_automation.php` allows authenticated users to exploit these SQL injection vulnerabilities to perform privilege escalation and remote code execution. In `api_automation.php` line 856, the `ge
debian
CVE-2005-1526P3HIGHCVSS 7.5PoCfixed in cacti 0.8.6e-1 (bookworm)2005
CVE-2005-1526 [HIGH] CVE-2005-1526: cacti - PHP remote file inclusion vulnerability in config_settings.php in Cacti before 0... PHP remote file inclusion vulnerability in config_settings.php in Cacti before 0.8.6e allows remote attackers to execute arbitrary PHP code via the config[include_path] parameter. Scope: local bookworm: resolved (fixed in 0.8.6e-1) bullseye: resolved (fixed in 0.8.6e-1) forky: resolved (fixed in 0.8.6e-1) sid: resolved (fixed in 0.8.6e-1) trixie: resolved (fixed in 0.8.
debian
CVE-2010-1431P3HIGHCVSS 7.5PoCfixed in cacti 0.8.7e-3 (bookworm)2010
CVE-2010-1431 [HIGH] CVE-2010-1431: cacti - SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier ... SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the export_item_id parameter. Scope: local bookworm: resolved (fixed in 0.8.7e-3) bullseye: resolved (fixed in 0.8.7e-3) forky: resolved (fixed in 0.8.7e-3) sid: resolved (fixed in 0.8.7e-3) trixie: resolved (fixed in 0.8.7e-3)
debian
CVE-2006-0147P3MEDIUMCVSS 7.5PoCfixed in cacti 0.8.6d-1 (bookworm)2006
CVE-2006-0147 [HIGH] CVE-2006-0147: cacti - Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb f... Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable
debian
CVE-2025-66399P2HIGHCVSS 7.4fixed in cacti 1.2.30+ds1-1 (forky)2025
CVE-2025-66399 [HIGH] CVE-2025-66399: cacti - Cacti is an open source performance and fault management framework. Prior to 1.2... Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configuration functionality. An authenticated Cacti user can supply crafted SNMP community strings containing control characters (including newlines) that are accepted, stored verbatim in the database, and later embedded into backen
debian
CVE-2024-54146P2LOWCVSS 7.6fixed in cacti 1.2.28+ds1-4 (forky)2024
CVE-2024-54146 [HIGH] CVE-2024-54146: cacti - Cacti is an open source performance and fault management framework. Cacti has a ... Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the template function of host_templates.php using the graph_template parameter. This vulnerability is fixed in 1.2.29. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 1.2.28+ds1-4) sid: resolved (fixed in 1.2.28+ds1-4) trixie: res
debian
Debian Cacti vulnerabilities | cvebase