Debian Cacti vulnerabilities
155 known vulnerabilities affecting debian/cacti.
Total CVEs
155
CISA KEV
1
actively exploited
Public exploits
25
Exploited in wild
3
Severity breakdown
CRITICAL10HIGH50MEDIUM72LOW23
Vulnerabilities
Page 4 of 8
CVE-2015-8369P3HIGHCVSS 7.5fixed in cacti 0.8.8f+ds1-3 (bookworm)2015
CVE-2015-8369 [HIGH] CVE-2015-8369: cacti - SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and ...
SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a properties action to graph.php.
Scope: local
bookworm: resolved (fixed in 0.8.8f+ds1-3)
bullseye: resolved (fixed in 0.8.8f+ds1-3)
forky: resolved (fixed in 0.8.8f+ds1-3)
sid: resolved (fixed in 0
debian
CVE-2015-4454P3HIGHCVSS 7.5fixed in cacti 0.8.8d+ds1-1 (bookworm)2015
CVE-2015-4454 [HIGH] CVE-2015-4454: cacti - SQL injection vulnerability in the get_hash_graph_template function in lib/funct...
SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.
Scope: local
bookworm: resolved (fixed in 0.8.8d+ds1-1)
bullseye: resolved (fixed in 0.8.8d+ds1-1)
forky: resolved (fixed in 0.8.8d+ds1-1)
sid
debian
CVE-2015-4634P3HIGHCVSS 7.5fixed in cacti 0.8.8e+ds1-1 (bookworm)2015
CVE-2015-4634 [HIGH] CVE-2015-4634: cacti - SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote a...
SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
Scope: local
bookworm: resolved (fixed in 0.8.8e+ds1-1)
bullseye: resolved (fixed in 0.8.8e+ds1-1)
forky: resolved (fixed in 0.8.8e+ds1-1)
sid: resolved (fixed in 0.8.8e+ds1-1)
trixie: resolved (fixed in 0.8.8e+ds1-
debian
CVE-2013-1434P3HIGHCVSS 7.5fixed in cacti 0.8.8b+dfsg-1 (bookworm)2013
CVE-2013-1434 [HIGH] CVE-2013-1434: cacti - Multiple SQL injection vulnerabilities in (1) api_poller.php and (2) utility.php...
Multiple SQL injection vulnerabilities in (1) api_poller.php and (2) utility.php in Cacti before 0.8.8b allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.8.8b+dfsg-1)
bullseye: resolved (fixed in 0.8.8b+dfsg-1)
forky: resolved (fixed in 0.8.8b+dfsg-1)
sid: resolved (fixed in 0.8.8b+dfsg-1)
trixi
debian
CVE-2010-2092P3HIGHCVSS 7.5fixed in cacti 0.8.7e-4 (bookworm)2010
CVE-2010-2092 [HIGH] CVE-2010-2092: cacti - SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remo...
SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via a crafted rra_id parameter in a GET request in conjunction with a valid rra_id value in a POST request or a cookie, which causes the POST or cookie value to bypass the validation routine, but inserts the $_GET value into the resulting query.
debian
CVE-2010-2544P4MEDIUMCVSS 4.3PoCfixed in cacti 0.8.7g-1 (bookworm)2010
CVE-2010-2544 [MEDIUM] CVE-2010-2544: cacti - Cross-site scripting (XSS) vulnerability in utilities.php in Cacti before 0.8.7g...
Cross-site scripting (XSS) vulnerability in utilities.php in Cacti before 0.8.7g, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.
Scope: local
bookworm: resolved (fixed in 0.8.7g-1)
bullseye: resolved (fixed in 0.8.7g-1)
forky: resolved (fixed in 0
debian
CVE-2010-2543P4MEDIUMCVSS 4.3PoCfixed in cacti 0.8.7g-1 (bookworm)2010
CVE-2010-2543 [MEDIUM] CVE-2010-2543: cacti - Cross-site scripting (XSS) vulnerability in include/top_graph_header.php in Cact...
Cross-site scripting (XSS) vulnerability in include/top_graph_header.php in Cacti before 0.8.7g allows remote attackers to inject arbitrary web script or HTML via the graph_start parameter to graph.php. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-4032.2.b.
Scope: local
bookworm: resolved (fixed in 0.8.7g-1)
bullseye: resolved (fixed in 0.8
debian
CVE-2011-4824P3HIGHCVSS 7.5fixed in cacti 0.8.7i-1 (bookworm)2011
CVE-2011-4824 [HIGH] CVE-2011-4824: cacti - SQL injection vulnerability in auth_login.php in Cacti before 0.8.7h allows remo...
SQL injection vulnerability in auth_login.php in Cacti before 0.8.7h allows remote attackers to execute arbitrary SQL commands via the login_username parameter.
Scope: local
bookworm: resolved (fixed in 0.8.7i-1)
bullseye: resolved (fixed in 0.8.7i-1)
forky: resolved (fixed in 0.8.7i-1)
sid: resolved (fixed in 0.8.7i-1)
trixie: resolved (fixed in 0.8.7i-1)
debian
CVE-2014-2328P3MEDIUMCVSS 6.5fixed in cacti 0.8.8b+dfsg-4 (bookworm)2014
CVE-2014-2328 [MEDIUM] CVE-2014-2328: cacti - lib/graph_export.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote authenti...
lib/graph_export.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.8.8b+dfsg-4)
bullseye: resolved (fixed in 0.8.8b+dfsg-4)
forky: resolved (fixed in 0.8.8b+dfsg-4)
sid: resolved (fixed in 0.8.8b+dfsg-4)
trixie: resolved (
debian
CVE-2025-24368P3MEDIUMCVSS 6.9fixed in cacti 1.2.24+ds1-1+deb12u5 (bookworm)2025
CVE-2025-24368 [MEDIUM] CVE-2025-24368: cacti - Cacti is an open source performance and fault management framework. Some of the ...
Cacti is an open source performance and fault management framework. Some of the data stored in automation_tree_rules.php is not thoroughly checked and is used to concatenate the SQL statement in build_rule_item_filter() function from lib/api_automation.php, resulting in SQL injection. This vulnerability is fixed in 1.2.29.
Scope: local
bookworm: resolved (fixed in 1
debian
CVE-2024-43362P3HIGHCVSS 7.3fixed in cacti 1.2.24+ds1-1+deb12u5 (bookworm)2024
CVE-2024-43362 [HIGH] CVE-2024-43362: cacti - Cacti is an open source performance and fault management framework. The `fileurl...
Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `links.php` . Morever, the said fileurl is placed in some html code which is passed to the `print` function in `link.php` and `index.php`, finally leading to stored XSS. Users with the privilege to create external links ca
debian
CVE-2006-0806P4MEDIUMCVSS 4.3PoCfixed in cacti 0.8.6d-1 (bookworm)2006
CVE-2006-0806 [MEDIUM] CVE-2006-0806: cacti - Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in mu...
Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF.
Scope: local
bookworm: resolved (fixed in 0.8.6d-1)
bullseye: resolved (fixed in 0.8.6
debian
CVE-2008-0783P4LOWCVSS 4.3PoCfixed in cacti 0.8.7b-1 (bookworm)2008
CVE-2008-0783 [MEDIUM] CVE-2008-0783: cacti - Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b...
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary web script or HTML via (1) the view_type parameter to graph.php; (2) the filter parameter to graph_view.php; (3) the action parameter to the draw_navigation_text function in lib/functions.php, reachable through index.php (
debian
CVE-2013-5589P3HIGHCVSS 7.5fixed in cacti 0.8.8b+dfsg-3 (bookworm)2013
CVE-2013-5589 [HIGH] CVE-2013-5589: cacti - SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows...
SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
Scope: local
bookworm: resolved (fixed in 0.8.8b+dfsg-3)
bullseye: resolved (fixed in 0.8.8b+dfsg-3)
forky: resolved (fixed in 0.8.8b+dfsg-3)
sid: resolved (fixed in 0.8.8b+dfsg-3)
trixie: resolved (fixed in 0.8.8b+dfs
debian
CVE-2010-1645P3MEDIUMCVSS 6.5fixed in cacti 0.8.7g-1 (bookworm)2010
CVE-2010-1645 [MEDIUM] CVE-2010-1645: cacti - Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solutio...
Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in (1) the FQDN field of a Device or (2) the Vertical Label field of a Graph Template.
Scope: local
bookworm: resolved (fixed in 0.8.7g-1)
bullseye: resolved (fixed in 0.
debian
CVE-2006-6799P3HIGHCVSS 7.5fixed in cacti 0.8.6i-3 (bookworm)2006
CVE-2006-6799 [HIGH] CVE-2006-6799: cacti - SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv...
SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php. NOTE: this issue can be leveraged to execute arbitrary commands since the SQL query results are later used in the polling_items array and popen function.
Scope: local
debian
CVE-2023-37543P3MEDIUMCVSS 4.3fixed in cacti 1.2.6+ds1-1 (bookworm)2023
CVE-2023-37543 [MEDIUM] CVE-2023-37543: cacti - Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing ...
Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php. This is a different vulnerability than CVE-2019-16723.
Scope: local
bookworm: resolved (fixed in 1.2.6+ds1-1)
bullseye: resolved (fixed in 1.2.6+ds1-1)
forky: resolved (fixed in 1.2.6+ds1-1)
sid: resolved (fixed in 1.2
debian
CVE-2007-6035P3MEDIUMCVSS 7.5fixed in cacti 0.8.7a-1 (bookworm)2007
CVE-2007-6035 [HIGH] CVE-2007-6035: cacti - SQL injection vulnerability in graph.php in Cacti before 0.8.7a allows remote at...
SQL injection vulnerability in graph.php in Cacti before 0.8.7a allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
Scope: local
bookworm: resolved (fixed in 0.8.7a-1)
bullseye: resolved (fixed in 0.8.7a-1)
forky: resolved (fixed in 0.8.7a-1)
sid: resolved (fixed in 0.8.7a-1)
trixie: resolved (fixed in 0.8.7a-1)
debian
CVE-2015-8377P3MEDIUMCVSS 6.5fixed in cacti 0.8.8f+ds1-4 (bookworm)2015
CVE-2015-8377 [MEDIUM] CVE-2015-8377: cacti - SQL injection vulnerability in the host_new_graphs_save function in graphs_new.p...
SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted serialized data in the selected_graphs_array parameter in a save action.
Scope: local
bookworm: resolved (fixed in 0.8.8f+ds1-4)
bullseye: resolved (fixed in 0.8.8f+ds1-4)
forky:
debian
CVE-2023-46490P3MEDIUMCVSS 6.5fixed in cacti 1.2.26+ds1-1 (forky)2023
CVE-2023-46490 [MEDIUM] CVE-2023-46490: cacti - SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain ...
SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers.php function.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.2.26+ds1-1)
sid: resolved (fixed in 1.2.26+ds1-1)
trixie: resolved (fixed in 1.2.26+ds1-1)
debian