← Back

Cacti

cacti

Vendor: Cacti • 152 CVEs

CVEs (152)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cacti
1Cacti
May 13, 2026
Oct 11, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.
1Cacti
1Cacti
May 13, 2026
Aug 21, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
1Cacti
1Cacti
May 13, 2026
Aug 18, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.
1Cacti
1Cacti
May 13, 2026
Aug 1, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the...Show more
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. NOTE: this vulnerability exists because of an incomplete fix (lack of the htmlspecialchars ENT_QUOTES flag) for CVE-2017-11163.Show less
1Cacti
1Cacti
May 13, 2026
Aug 1, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.
1Cacti
1Cacti
May 13, 2026
Jul 27, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
1Cacti
1Cacti
May 13, 2026
Jul 17, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.
1Cacti
1Cacti
May 13, 2026
Jul 17, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters.
1Cacti
1Cacti
May 13, 2026
Jul 10, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel...Show more
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.Show less
1Cacti
1Cacti
May 13, 2026
Jul 6, 2017
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_val...Show more
Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php.Show less
2Cacti
Opensuse
3Cacti
LeapOpensuse
May 6, 2026
Apr 13, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
1Cacti
1Cacti
May 6, 2026
Apr 12, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the parent_id parameter in an item_edit action.
1Cacti
1Cacti
May 6, 2026
Apr 11, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action.
1Cacti
1Cacti
May 6, 2026
Apr 11, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter.
1Cacti
1Cacti
May 6, 2026
Dec 17, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a properties action to graph.php.
1Cacti
1Cacti
May 6, 2026
Dec 15, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted serialized data in the select...Show more
SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted serialized data in the selected_graphs_array parameter in a save action.Show less
1Cacti
1Cacti
May 6, 2026
Aug 11, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
1Cacti
1Cacti
May 6, 2026
Jul 10, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in settings.php in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
2Cacti
Fedoraproject
2Cacti
Fedora
May 6, 2026
Jun 17, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templ...Show more
SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.Show less
2Cacti
Fedoraproject
2Cacti
Fedora
May 6, 2026
Jun 17, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving a cdef id.