Debian Cacti vulnerabilities
155 known vulnerabilities affecting debian/cacti.
Total CVEs
155
CISA KEV
1
actively exploited
Public exploits
25
Exploited in wild
3
Severity breakdown
CRITICAL10HIGH50MEDIUM72LOW23
Vulnerabilities
Page 6 of 8
CVE-2020-13231P4MEDIUMCVSS 6.5fixed in cacti 1.2.11+ds1-1 (bookworm)2020
CVE-2020-13231 [MEDIUM] CVE-2020-13231: cacti - In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin em...
In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change.
Scope: local
bookworm: resolved (fixed in 1.2.11+ds1-1)
bullseye: resolved (fixed in 1.2.11+ds1-1)
forky: resolved (fixed in 1.2.11+ds1-1)
sid: resolved (fixed in 1.2.11+ds1-1)
trixie: resolved (fixed in 1.2.11+ds1-1)
debian
CVE-2020-25706P4MEDIUMCVSS 5.4fixed in cacti 1.2.14+ds1-1 (bookworm)2020
CVE-2020-25706 [MEDIUM] CVE-2020-25706: cacti - A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti...
A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field
Scope: local
bookworm: resolved (fixed in 1.2.14+ds1-1)
bullseye: resolved (fixed in 1.2.14+ds1-1)
forky: resolved (fixed in 1.2.14+ds1-1)
sid: resolved (fixed in 1.2.14+ds1-1)
trixie:
debian
CVE-2023-39513P4MEDIUMCVSS 6.1fixed in cacti 1.2.24+ds1-1+deb12u2 (bookworm)2023
CVE-2023-39513 [MEDIUM] CVE-2023-39513: cacti - Cacti is an open source operational monitoring and fault management framework. A...
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-t
debian
CVE-2024-31443P4MEDIUMCVSS 5.7fixed in cacti 1.2.24+ds1-1+deb12u3 (bookworm)2024
CVE-2024-31443 [MEDIUM] CVE-2024-31443: cacti - Cacti provides an operational monitoring and fault management framework. Prior t...
Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_pane_tree()` function from `lib/html.php` , finally resulting in cross-site scripting. Version 1.2.27 contains a patch
debian
CVE-2024-47875P4CRITICALCVSS 10.0fixed in cacti 1.2.24+ds1-1+deb12u2 (bookworm)2024
CVE-2024-47875 [CRITICAL] CVE-2024-47875: cacti - DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathM...
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.
Scope: local
bookworm: resolved (fixed in 1.2.24+ds1-1+deb12u2)
bullseye: resolved (fixed in 1.2.16+ds1-2+deb11u5)
forky: resolved (fixed in 1.2.26+ds1-1)
sid: resolved (fixed in
debian
CVE-2024-27082P4HIGHCVSS 7.6fixed in cacti 1.2.24+ds1-1+deb12u5 (bookworm)2024
CVE-2024-27082 [HIGH] CVE-2024-27082: cacti - Cacti provides an operational monitoring and fault management framework. Version...
Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server and served to users who access a particular page. Version 1.2.27 contains a patch for the issue.
Scope: local
bookworm:
debian
CVE-2023-39360P4MEDIUMCVSS 6.1fixed in cacti 1.2.24+ds1-1+deb12u2 (bookworm)2023
CVE-2023-39360 [MEDIUM] CVE-2023-39360: cacti - Cacti is an open source operational monitoring and fault management framework.Af...
Cacti is an open source operational monitoring and fault management framework.Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data. The vulnerability is found in `graphs_new.php`. Several validations are performed, but the `returnto` parameter is directly passed to `form_save_button`. In order
debian
CVE-2023-39514P4MEDIUMCVSS 6.1fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39514 [MEDIUM] CVE-2023-39514: cacti - Cacti is an open source operational monitoring and fault management framework. A...
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-t
debian
CVE-2022-48547P4MEDIUMCVSS 6.1fixed in cacti 0.8.7i-1 (bookworm)2022
CVE-2022-48547 [MEDIUM] CVE-2022-48547: cacti - A reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier...
A reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers to inject arbitrary web script or HTML in the "ref" parameter at auth_changepassword.php.
Scope: local
bookworm: resolved (fixed in 0.8.7i-1)
bullseye: resolved (fixed in 0.8.7i-1)
forky: resolved (fixed in 0.8.7i-1)
sid: resolved (fixed in 0.8.7i
debian
CVE-2007-3112P4LOWCVSS 7.8fixed in cacti 0.8.6j-1.1 (bookworm)2007
CVE-2007-3112 [HIGH] CVE-2007-3112: cacti - graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote auth...
graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_start or (2) graph_end parameter, different vectors than CVE-2007-3113.
Scope: local
bookworm: resolved (fixed in 0.8.6j-1.1)
bullseye: resolved (fixed in 0.8.6j-1.1)
forky: resolved (fixed in 0
debian
CVE-2017-11691P4MEDIUMCVSS 5.4fixed in cacti 1.1.15+ds1-1 (bookworm)2017
CVE-2017-11691 [MEDIUM] CVE-2017-11691: cacti - Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 all...
Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
Scope: local
bookworm: resolved (fixed in 1.1.15+ds1-1)
bullseye: resolved (fixed in 1.1.15+ds1-1)
forky: resolved (fixed in 1.1.15+ds1-1)
sid: resolved (fixed in 1.1.15+ds1-1)
trixie:
debian
CVE-2021-3816P4MEDIUMCVSS 5.4fixed in cacti 1.2.1+ds1-1 (bookworm)2021
CVE-2021-3816 [MEDIUM] CVE-2021-3816: cacti - Cacti 1.1.38 allows authenticated users with User Management permissions to inje...
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a new group via "Copy" method at user_group_admin.php.
Scope: local
bookworm: resolved (fixed in 1.2.1+ds1-1)
bullseye: resolved (fixed in 1.2.1+ds1-1)
forky: resolved (fixed in 1.2.1+ds1-1)
sid: resolved (fixed in 1.2.1+ds
debian
CVE-2017-12927P4MEDIUMCVSS 6.1fixed in cacti 1.1.17+ds1-2 (bookworm)2017
CVE-2017-12927 [MEDIUM] CVE-2017-12927: cacti - A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parame...
A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.
Scope: local
bookworm: resolved (fixed in 1.1.17+ds1-2)
bullseye: resolved (fixed in 1.1.17+ds1-2)
forky: resolved (fixed in 1.1.17+ds1-2)
sid: resolved (fixed in 1.1.17+ds1-2)
trixie: resolved (fixed in 1.1.17+ds1-2)
debian
CVE-2022-41444P4MEDIUMCVSS 6.1fixed in cacti 1.2.22+ds1-1 (bookworm)2022
CVE-2022-41444 [MEDIUM] CVE-2022-41444: cacti - Cross Site Scripting (XSS) vulnerability in Cacti 1.2.21 via crafted POST reques...
Cross Site Scripting (XSS) vulnerability in Cacti 1.2.21 via crafted POST request to graphs_new.php.
Scope: local
bookworm: resolved (fixed in 1.2.22+ds1-1)
bullseye: resolved (fixed in 1.2.16+ds1-2+deb11u4)
forky: resolved (fixed in 1.2.22+ds1-1)
sid: resolved (fixed in 1.2.22+ds1-1)
trixie: resolved (fixed in 1.2.22+ds1-1)
debian
CVE-2017-12066P4MEDIUMCVSS 5.4fixed in cacti 1.1.16+ds1-1 (bookworm)2017
CVE-2017-12066 [MEDIUM] CVE-2017-12066: cacti - Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before...
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. NOTE: this vulnerability exists because of an incomplete fix (lack of the htmlspecialchars ENT_QUOTES flag) for CVE-2017-11163
debian
CVE-2018-20726P4LOWCVSS 5.4fixed in cacti 1.2.1+ds1-1 (bookworm)2018
CVE-2018-20726 [MEDIUM] CVE-2018-20726: cacti - A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in ...
A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.
Scope: local
bookworm: resolved (fixed in 1.2.1+ds1-1)
bullseye: resolved (fixed in 1.2.1+ds1-1)
forky: resolved (fixed in 1.2.1+ds1-1)
sid: resolved (fixed in 1.2.1+ds1-1)
trix
debian
CVE-2018-10060P4LOWCVSS 5.4fixed in cacti 1.1.37+ds1-1 (bookworm)2018
CVE-2018-10060 [MEDIUM] CVE-2018-10060: cacti - Cacti before 1.1.37 has XSS because it does not properly reject unintended chara...
Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php.
Scope: local
bookworm: resolved (fixed in 1.1.37+ds1-1)
bullseye: resolved (fixed in 1.1.37+ds1-1)
forky: resolved (fixed in 1.1.37+ds1-1)
sid: resolved (fixed in 1.1.37+ds1-1)
trixie: resolved (fixed in 1.1.37+ds1-
debian
CVE-2021-23225P4MEDIUMCVSS 5.4fixed in cacti 1.2.1+ds1-1 (bookworm)2021
CVE-2021-23225 [MEDIUM] CVE-2021-23225: cacti - Cacti 1.1.38 allows authenticated users with User Management permissions to inje...
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.
Scope: local
bookworm: resolved (fixed in 1.2.1+ds1-1)
bullseye: resolved (fixed in 1.2.1+ds1-1)
forky: resolved (fixed in 1.2.1+ds1-1)
sid: resolved (fixed in 1
debian
CVE-2019-16723P4MEDIUMCVSS 4.3fixed in cacti 1.2.7+ds1-1 (bookworm)2019
CVE-2019-16723 [MEDIUM] CVE-2019-16723: cacti - In Cacti through 1.2.6, authenticated users may bypass authorization checks (for...
In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.
Scope: local
bookworm: resolved (fixed in 1.2.7+ds1-1)
bullseye: resolved (fixed in 1.2.7+ds1-1)
forky: resolved (fixed in 1.2.7+ds1-1)
sid: resolved (fixed in 1.2.7+ds1-1)
trixie: resolved (f
debian
CVE-2019-11025P4LOWCVSS 5.4fixed in cacti 1.2.2+ds1-2 (bookworm)2019
CVE-2019-11025 [MEDIUM] CVE-2019-11025: cacti - In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs befo...
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.
Scope: local
bookworm: resolved (fixed in 1.2.2+ds1-2)
bullseye: resolved (fixed in 1.2.2+ds1-2)
forky: resolved (fixed in 1.2.2+ds1-2)
sid: resolved (fixed in 1.2.2+ds1-2)
tri
debian