Debian Cacti vulnerabilities
155 known vulnerabilities affecting debian/cacti.
Total CVEs
155
CISA KEV
1
actively exploited
Public exploits
25
Exploited in wild
3
Severity breakdown
CRITICAL10HIGH50MEDIUM72LOW23
Vulnerabilities
Page 3 of 8
CVE-2016-3172P3HIGHCVSS 8.8fixed in cacti 0.8.8g+ds1-2 (bookworm)2016
CVE-2016-3172 [HIGH] CVE-2016-3172: cacti - SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remot...
SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the parent_id parameter in an item_edit action.
Scope: local
bookworm: resolved (fixed in 0.8.8g+ds1-2)
bullseye: resolved (fixed in 0.8.8g+ds1-2)
forky: resolved (fixed in 0.8.8g+ds1-2)
sid: resolved (fixed in 0.8.8g+ds1-2)
trixie:
debian
CVE-2014-2709P3HIGHCVSS 7.5fixed in cacti 0.8.8b+dfsg-4 (bookworm)2014
CVE-2014-2709 [HIGH] CVE-2014-2709: cacti - lib/rrd.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to exec...
lib/rrd.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified parameters.
Scope: local
bookworm: resolved (fixed in 0.8.8b+dfsg-4)
bullseye: resolved (fixed in 0.8.8b+dfsg-4)
forky: resolved (fixed in 0.8.8b+dfsg-4)
sid: resolved (fixed in 0.8.8b+dfsg-4)
trixie: resolved (fixed in 0.8.8b+df
debian
CVE-2014-4000P3LOWCVSS 8.8fixed in cacti 0.8.8e+ds1-1 (bookworm)2014
CVE-2014-4000 [HIGH] CVE-2014-4000: cacti - Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injec...
Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object, related to calling unserialize(stripslashes()).
Scope: local
bookworm: resolved (fixed in 0.8.8e+ds1-1)
bullseye: resolved (fixed in 0.8.8e+ds1-1)
forky: resolved (fixed in 0.8.8e+ds1-1)
sid: resolved (fixed in 0.8.
debian
CVE-2024-43365P3MEDIUMCVSS 5.7fixed in cacti 1.2.24+ds1-1+deb12u5 (bookworm)2024
CVE-2024-43365 [MEDIUM] CVE-2024-43365: cacti - Cacti is an open source performance and fault management framework. The`consolen...
Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external links in links.php . Morever, the said consolenewsection parameter is stored in the database and reflected back to user in `index.php`, finally leading to stored XSS. Users with the privilege to create external links can
debian
CVE-2016-10700P3HIGHCVSS 8.8fixed in cacti 0.8.8h+ds1-5 (bookworm)2016
CVE-2016-10700 [HIGH] CVE-2016-10700: cacti - auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use w...
auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database, because the guest user is not considered. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-2313.
Scope: local
bookworm: resolved (fixed in 0.8.8h+ds1-5)
bull
debian
CVE-2016-3659P3HIGHCVSS 8.8fixed in cacti 0.8.8h+ds1-1 (bookworm)2016
CVE-2016-3659 [HIGH] CVE-2016-3659: cacti - SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote aut...
SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter.
Scope: local
bookworm: resolved (fixed in 0.8.8h+ds1-1)
bullseye: resolved (fixed in 0.8.8h+ds1-1)
forky: resolved (fixed in 0.8.8h+ds1-1)
sid: resolved (fixed in 0.8.8h+ds1-1)
trixie: resolved (fixed in 0.
debian
CVE-2025-22604P3CRITICALCVSS 9.1fixed in cacti 1.2.24+ds1-1+deb12u5 (bookworm)2025
CVE-2025-22604 [CRITICAL] CVE-2025-22604: cacti - Cacti is an open source performance and fault management framework. Due to a fla...
Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject malformed OIDs in the response. When processed by ss_net_snmp_disk_io() or ss_net_snmp_disk_bytes(), a part of each OID will be used as a key in an array that is used as part of a system command, causing a command execu
debian
CVE-2013-1435P3HIGHCVSS 7.5fixed in cacti 0.8.8b+dfsg-1 (bookworm)2013
CVE-2013-1435 [HIGH] CVE-2013-1435: cacti - (1) snmp.php and (2) rrd.php in Cacti before 0.8.8b allows remote attackers to e...
(1) snmp.php and (2) rrd.php in Cacti before 0.8.8b allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.8.8b+dfsg-1)
bullseye: resolved (fixed in 0.8.8b+dfsg-1)
forky: resolved (fixed in 0.8.8b+dfsg-1)
sid: resolved (fixed in 0.8.8b+dfsg-1)
trixie: resolved (fixed in 0.8.8b+df
debian
CVE-2023-30534P4MEDIUMCVSS 4.3PoCfixed in cacti 1.2.25+ds1-1 (forky)2023
CVE-2023-30534 [MEDIUM] CVE-2023-30534: cacti - Cacti is an open source operational monitoring and fault management framework. T...
Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory (phpseclib), the necessary gadgets are not included, making them inaccessible and the insecure deserializations not exploitable. Each instance of ins
debian
CVE-2024-54145P3MEDIUMCVSS 6.3fixed in cacti 1.2.24+ds1-1+deb12u5 (bookworm)2024
CVE-2024-54145 [MEDIUM] CVE-2024-54145: cacti - Cacti is an open source performance and fault management framework. Cacti has a ...
Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the get_discovery_results function of automation_devices.php using the network parameter. This vulnerability is fixed in 1.2.29.
Scope: local
bookworm: resolved (fixed in 1.2.24+ds1-1+deb12u5)
bullseye: resolved (fixed in 1.2.16+ds1-2+deb11u5)
forky: resolv
debian
CVE-2025-26520P3LOWCVSS 7.6fixed in cacti 1.2.30+ds1-1 (forky)2025
CVE-2025-26520 [HIGH] CVE-2025-26520: cacti - Cacti through 1.2.29 allows SQL injection in the template function in host_templ...
Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists because of an incomplete fix for CVE-2024-54146.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1.2.30+ds1-1)
sid: resolved (fixed in 1.2.30+ds1-1)
trixie: resolved (fixed in 1.2.30+ds1-1)
debian
CVE-2017-16641P3HIGHCVSS 7.2fixed in cacti 1.1.27+ds1-3 (bookworm)2017
CVE-2017-16641 [HIGH] CVE-2017-16641: cacti - lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execut...
lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php.
Scope: local
bookworm: resolved (fixed in 1.1.27+ds1-3)
bullseye: resolved (fixed in 1.1.27+ds1-3)
forky: resolved (fixed in 1.1.27+ds1-3)
sid: resolved (fixed in 1.1.27+ds1-3)
trixie: resolve
debian
CVE-2024-48910P3CRITICALCVSS 9.1fixed in cacti 1.2.24+ds1-1+deb12u2 (bookworm)2024
CVE-2024-48910 [CRITICAL] CVE-2024-48910: cacti - DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathM...
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.
Scope: local
bookworm: resolved (fixed in 1.2.24+ds1-1+deb12u2)
bullseye: resolved (fixed in 1.2.16+ds1-2+deb11u5)
forky: resolved (fixed in 1.2.26+ds1-1)
sid: resolved (fixed in 1.2.26+ds
debian
CVE-2024-31459P3HIGHCVSS 8.0fixed in cacti 1.2.24+ds1-1+deb12u3 (bookworm)2024
CVE-2024-31459 [HIGH] CVE-2024-31459: cacti - Cacti provides an operational monitoring and fault management framework. Prior t...
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.php` file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. There is a file inclusion issue with the `api_plugin_hook()` function in the `lib/plugin.php` file, which reads the plugin_
debian
CVE-2015-4342P3HIGHCVSS 7.5fixed in cacti 0.8.8d+ds1-1 (bookworm)2015
CVE-2015-4342 [HIGH] CVE-2015-4342: cacti - SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to ex...
SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving a cdef id.
Scope: local
bookworm: resolved (fixed in 0.8.8d+ds1-1)
bullseye: resolved (fixed in 0.8.8d+ds1-1)
forky: resolved (fixed in 0.8.8d+ds1-1)
sid: resolved (fixed in 0.8.8d+ds1-1)
trixie: resolved (fixed in 0.8.8d+ds1-1)
debian
CVE-2019-17358P3HIGHCVSS 8.1fixed in cacti 1.2.8+ds1-1 (bookworm)2019
CVE-2019-17358 [HIGH] CVE-2019-17358: cacti - Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsaf...
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP module.
Scope: local
bookworm: resolved (fixed in 1.2.8+ds1-1)
bullsey
debian
CVE-2017-16660P3HIGHCVSS 7.2fixed in cacti 1.1.27+ds1-3 (bookworm)2017
CVE-2017-16660 [HIGH] CVE-2017-16660: cacti - Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code E...
Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.
Scope: local
bookworm: resolved (fixed in 1.1.27+ds1-3)
bullseye: resolved (fixed in 1.1.27+ds1-3)
forky: resolved (fixed in 1.1.27+ds1-3)
sid:
debian
CVE-2014-5262P3HIGHCVSS 7.5fixed in cacti 0.8.8b+dfsg-8 (bookworm)2014
CVE-2014-5262 [HIGH] CVE-2014-5262: cacti - SQL injection vulnerability in the graph settings script (graph_settings.php) in...
SQL injection vulnerability in the graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.8.8b+dfsg-8)
bullseye: resolved (fixed in 0.8.8b+dfsg-8)
forky: resolved (fixed in 0.8.8b+dfsg-8)
sid: resolved (fixed in 0.8.8b+dfsg-8)
tr
debian
CVE-2014-2708P3HIGHCVSS 7.5fixed in cacti 0.8.8b+dfsg-4 (bookworm)2014
CVE-2014-2708 [HIGH] CVE-2014-2708: cacti - Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8...
Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to execute arbitrary SQL commands via the (1) graph_start, (2) graph_end, (3) graph_height, (4) graph_width, (5) graph_nolegend, (6) print_source, (7) local_graph_id, or (8) rra_id parameter.
Scope: local
bookworm: resolved (fixed in 0.8.8b+dfsg-4)
bulls
debian
CVE-2009-4032P4LOWCVSS 4.3PoCfixed in cacti 0.8.7e-1.1 (bookworm)2009
CVE-2009-4032 [MEDIUM] CVE-2009-4032: cacti - Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote...
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) graph.php, (2) include/top_graph_header.php, (3) lib/html_form.php, and (4) lib/timespan_settings.php, as demonstrated by the (a) graph_end or (b) graph_start parameters to graph.php; (c) the date1 parameter in a
debian