Nagios Xi vulnerabilities
76 known vulnerabilities affecting nagios/xi.
Total CVEs
76
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH25MEDIUM46
Vulnerabilities
Page 3 of 4
CVE-2023-7316P4MEDIUMCVSS 5.4fixed in 2024R12025-10-30
CVE-2023-7316 [MEDIUM] CWE-79 CVE-2023-7316: Nagios XI versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Graph Explor
Nagios XI versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Graph Explorer component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2024-14000P4MEDIUMCVSS 5.4fixed in 2024R1.1.32025-10-30
CVE-2024-14000 [MEDIUM] CWE-79 CVE-2024-14000: Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity
Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity Planning Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2024-14001P4MEDIUMCVSS 5.4fixed in 2024R1.1.32025-10-30
CVE-2024-14001 [MEDIUM] CWE-79 CVE-2024-14001: Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Executiv
Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Executive Summary Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2023-7315P4MEDIUMCVSS 5.4fixed in 5.11.32025-10-30
CVE-2023-7315 [MEDIUM] CWE-79 CVE-2023-7315: Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Graph Explor
Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Graph Explorer component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2023-7314P4MEDIUMCVSS 5.4fixed in 5.11.32025-10-30
CVE-2023-7314 [MEDIUM] CWE-79 CVE-2023-7314: Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Re
Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2021-47697P4MEDIUMCVSS 5.4fixed in 5.8.02025-10-30
CVE-2021-47697 [MEDIUM] CWE-79 CVE-2021-47697: Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via the Views feature
Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via the Views feature URL handling. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2021-47698P4MEDIUMCVSS 5.4fixed in 5.8.72025-11-03
CVE-2021-47698 [MEDIUM] CWE-79 CVE-2021-47698: Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting
Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling (escape_string()). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2022-50587P4MEDIUMCVSS 5.4fixed in 5.8.92025-10-30
CVE-2022-50587 [MEDIUM] CWE-79 CVE-2022-50587: Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) via the Apply Configu
Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) via the Apply Configuration error text. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2022-50586P4MEDIUMCVSS 5.4fixed in 5.8.92025-10-30
CVE-2022-50586 [MEDIUM] CWE-79 CVE-2022-50586: Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the BPI component
Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the BPI component via the info URL field. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2011-10040P4MEDIUMCVSS 5.4fixed in 2011R1.92025-10-30
CVE-2011-10040 [MEDIUM] CWE-79 CVE-2011-10040: Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the link-handl
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the link-handling functions used by status and report pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2022-50584P4MEDIUMCVSS 5.4fixed in 5.8.82025-10-30
CVE-2022-50584 [MEDIUM] CWE-79 CVE-2022-50584: The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.6 / Nagios XI 5.8.8 contains a
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.6 / Nagios XI 5.8.8 contains a cross-site scripting (XSS) vulnerability via the search and deletion interfaces. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2020-36865P4MEDIUMCVSS 5.4fixed in 5.7.22025-10-30
CVE-2020-36865 [MEDIUM] CWE-79 CVE-2020-36865: Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the BPI (Business
Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the BPI (Business Process Intelligence) component’s Config Management and Edit Config page. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2023-7318P4MEDIUMCVSS 5.4fixed in 2024R1.0.22025-10-30
CVE-2023-7318 [MEDIUM] CWE-79 CVE-2023-7318: Nagios XI versions prior to < 2024R1.0.2 are vulnerable to cross-site scripting (XSS) via the Nagios
Nagios XI versions prior to < 2024R1.0.2 are vulnerable to cross-site scripting (XSS) via the Nagios Core Command Expansion page. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2023-7313P4MEDIUMCVSS 5.4fixed in 5.11.32025-10-30
CVE-2023-7313 [MEDIUM] CWE-79 CVE-2023-7313: Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modific
Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modifications tool. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2011-10038P4MEDIUMCVSS 5.4fixed in 2011R1.92025-10-30
CVE-2011-10038 [MEDIUM] CWE-79 CVE-2011-10038: Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the recurring
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the recurring downtime script of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2016-15053P4MEDIUMCVSS 5.4fixed in 5.2.42025-10-30
CVE-2016-15053 [MEDIUM] CWE-79 CVE-2016-15053: Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the “My Reports”
Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the “My Reports” listing of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2016-15052P4MEDIUMCVSS 5.4fixed in 5.2.42025-10-30
CVE-2016-15052 [MEDIUM] CWE-79 CVE-2016-15052: Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Menu System o
Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Menu System of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2021-47691P4MEDIUMCVSS 5.4fixed in 5.8.22025-10-30
CVE-2021-47691 [MEDIUM] CWE-79 CVE-2021-47691: The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.1 / Nagios XI 5.8.2 contains mu
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.1 / Nagios XI 5.8.2 contains multiple cross-site scripting (XSS) vulnerabilities via the Services page affecting the config_name and service_description fields. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in
nvd
CVE-2021-47696P4MEDIUMCVSS 5.4fixed in 5.8.02025-10-30
CVE-2021-47696 [MEDIUM] CWE-79 CVE-2021-47696: Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via BPI config ID han
Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via BPI config ID handling. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2020-36864P4MEDIUMCVSS 5.4fixed in 5.7.22025-10-30
CVE-2020-36864 [MEDIUM] CWE-79 CVE-2020-36864: Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the background co
Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the background color settings in Dashboards. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd