Nagios Xi vulnerabilities
194 known vulnerabilities affecting nagios/nagios_xi.
Total CVEs
194
CISA KEV
4
actively exploited
Public exploits
26
Exploited in wild
8
Severity breakdown
CRITICAL26HIGH72MEDIUM94LOW2
Vulnerabilities
Page 8 of 10
CVE-2023-51072P4MEDIUMCVSS 5.4fixed in 2024v20242024-02-02
CVE-2023-51072 [MEDIUM] CWE-79 CVE-2023-51072: A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to an
A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious HTML or JavaScript code via the audio file upload functionality from the Operation Center section. This allows any authenticated user to execute arbitrary JavaScript code on behalf of
nvd
CVE-2011-10037P4MEDIUMCVSS 5.4≤ 2009v20112025-10-30
CVE-2011-10037 [MEDIUM] CWE-79 CVE-2011-10037: Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling o
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of xiwindow variables used to build permalinks in the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2024-13992P4MEDIUMCVSS 5.4fixed in 2024v2024-r1+2 more2025-10-31
CVE-2024-13992 [MEDIUM] CWE-79 CVE-2024-13992: Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user vis
Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link from another website. The vulnerable component, page-missing.php, fails to properly validate or escape user-supplied input, allowing an attacker to craft a malicious link that, when visited by a
nvd
CVE-2023-7316P4MEDIUMCVSS 5.4fixed in 20242025-10-30
CVE-2023-7316 [MEDIUM] CWE-79 CVE-2023-7316: Nagios XI versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Graph Explor
Nagios XI versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Graph Explorer component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2024-14000P4MEDIUMCVSS 5.4fixed in 2024v2024-r1+5 more2025-10-30
CVE-2024-14000 [MEDIUM] CWE-79 CVE-2024-14000: Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity
Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity Planning Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2024-14001P4MEDIUMCVSS 5.4fixed in 2024v2024-r1+5 more2025-10-30
CVE-2024-14001 [MEDIUM] CWE-79 CVE-2024-14001: Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Executiv
Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Executive Summary Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2023-7315P4MEDIUMCVSS 5.4fixed in 5.11.32025-10-30
CVE-2023-7315 [MEDIUM] CWE-79 CVE-2023-7315: Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Graph Explor
Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Graph Explorer component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2023-7314P4MEDIUMCVSS 5.4fixed in 5.11.32025-10-30
CVE-2023-7314 [MEDIUM] CWE-79 CVE-2023-7314: Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Re
Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2021-47697P4MEDIUMCVSS 5.4fixed in 5.8.02025-10-30
CVE-2021-47697 [MEDIUM] CWE-79 CVE-2021-47697: Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via the Views feature
Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via the Views feature URL handling. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2021-47698P4MEDIUMCVSS 5.4fixed in 5.8.72025-11-03
CVE-2021-47698 [MEDIUM] CWE-79 CVE-2021-47698: Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting
Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling (escape_string()). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2022-50587P4MEDIUMCVSS 5.4fixed in 5.8.92025-10-30
CVE-2022-50587 [MEDIUM] CWE-79 CVE-2022-50587: Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) via the Apply Configu
Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) via the Apply Configuration error text. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2022-50586P4MEDIUMCVSS 5.4fixed in 5.8.92025-10-30
CVE-2022-50586 [MEDIUM] CWE-79 CVE-2022-50586: Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the BPI component
Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the BPI component via the info URL field. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2011-10040P4MEDIUMCVSS 5.4≤ 2009v20112025-10-30
CVE-2011-10040 [MEDIUM] CWE-79 CVE-2011-10040: Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the link-handl
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the link-handling functions used by status and report pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2022-50584P4MEDIUMCVSS 5.4fixed in 5.8.82025-10-30
CVE-2022-50584 [MEDIUM] CWE-79 CVE-2022-50584: The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.6 / Nagios XI 5.8.8 contains a
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.6 / Nagios XI 5.8.8 contains a cross-site scripting (XSS) vulnerability via the search and deletion interfaces. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2020-36865P4MEDIUMCVSS 5.4fixed in 5.7.22025-10-30
CVE-2020-36865 [MEDIUM] CWE-79 CVE-2020-36865: Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the BPI (Business
Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the BPI (Business Process Intelligence) component’s Config Management and Edit Config page. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2018-20171P4MEDIUMCVSS 6.1fixed in 5.5.82018-12-17
CVE-2018-20171 [MEDIUM] CWE-79 CVE-2018-20171: An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/script
An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability.
nvd
CVE-2018-20172P4MEDIUMCVSS 6.1fixed in 5.5.82018-12-17
CVE-2018-20172 [MEDIUM] CWE-79 CVE-2018-20172: An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/sc
An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability.
nvd
CVE-2025-56432P4MEDIUMCVSS 6.1v2024-r22025-08-26
CVE-2025-56432 [MEDIUM] CWE-79 CVE-2025-56432: A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remo
A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in user's session via a specially crafted URL. The issue resides in a web component responsible for rendering performance-related data.
nvd
CVE-2023-7318P4MEDIUMCVSS 5.4fixed in 2024v20242025-10-30
CVE-2023-7318 [MEDIUM] CWE-79 CVE-2023-7318: Nagios XI versions prior to < 2024R1.0.2 are vulnerable to cross-site scripting (XSS) via the Nagios
Nagios XI versions prior to < 2024R1.0.2 are vulnerable to cross-site scripting (XSS) via the Nagios Core Command Expansion page. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2023-7313P4MEDIUMCVSS 5.4fixed in 5.11.32025-10-30
CVE-2023-7313 [MEDIUM] CWE-79 CVE-2023-7313: Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modific
Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modifications tool. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd