VendorsNagioslog_serverall versions
Vulnerabilities

Nagios Log Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2025-44823
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475.
Published 2025-10-07 · Analyzed
9.9EPSS 0.161
CVE-2025-34277
Nagios Log Server < 2024R1.3.1 RCE via Malformed Dashboard ID
Published 2025-10-30 · Analyzed
9.8EPSS 0.020
CVE-2025-34274
Nagios Log Server < 2024R2.0.3 Logstash Process Root Privileges
Published 2025-10-30 · Analyzed
9.8EPSS 0.019
CVE-2025-34271
Nagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over Plaintext
Published 2025-10-30 · Analyzed
9.8EPSS 0.007
CVE-2025-34298
Nagios Log Server < 2024R1.3.2 Set Email Privilege Escalation
Published 2025-10-30 · Analyzed
8.8EPSS 0.007
CVE-2023-7322
Nagios Log Server < 2024R1 Incorrect Authorization Granting Full API Access
Published 2025-10-30 · Analyzed
8.7EPSS 0.010
CVE-2025-34322
Nagios Log Server < 2026R1.0.1 Authenticated Command Injection via Natural Language Queries
Published 2025-11-17 · Modified
8.6EPSS 0.095
CVE-2025-44824
Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch service via a /nagioslogserver/index.php/api/system/stop?subsystem=elasticsearch call. The service stops even though "message": "Could not stop elasticsearch" is in the API response. This is GL:NLS#474.
Published 2025-10-07 · Analyzed
8.5EPSS 0.028
CVE-2025-34323
Nagios Log Server < 2026R1.0.1 Local Privilege Escalation via Writable Scripts and Sudo Rules
Published 2025-11-17 · Modified
8.5EPSS 0.003
CVE-2024-58273
Nagios Log Server < 2024R1.0.2 LPE from Apache/Backend Shell User to Root
Published 2025-10-30 · Analyzed
8.5EPSS 0.003
CVE-2025-29471
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.
Published 2025-04-15 · Analyzed
8.31 PoCEPSS 0.072
CVE-2025-34273
Nagios Log Server < 2024R2.0.3 Non-Admin Dashboard Deletion
Published 2025-10-30 · Analyzed
7.1EPSS 0.010
CVE-2025-34270
Nagios Log Server < 2024R2.0.2 AD/LDAP Import Password Not Obfuscated
Published 2025-10-30 · Analyzed
6.9EPSS 0.006
CVE-2025-34272
Nagios Log Server < 2024R2.0.3 Non-Empty Default Dashboard Fallback
Published 2025-10-30 · Analyzed
6.5EPSS 0.008
CVE-2020-25385
Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name parameter, which may impact users who open a maliciously crafted link or third-party web page.
Published 2021-01-20 · Modified
6.1EPSS 0.162
CVE-2019-15898
Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page.
Published 2019-09-03 · Modified
6.1EPSS 0.016
CVE-2021-35478
Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page.
Published 2021-07-27 · Modified
5.4EPSS 0.766
CVE-2020-16157
A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.
Published 2020-07-30 · Modified
5.4EPSS 0.144
CVE-2021-35479
Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. This affects users who open a crafted link or third-party web page.
Published 2021-07-27 · Modified
5.4EPSS 0.132
CVE-2016-15049
Nagios Log Server < 1.4.2 Dashboards Logs Table XSS
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2023-7323
Nagios Log Server < 2024R1 XSS via Create User Function
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2023-7321
Nagios Log Server < 2.1.14 XSS via Snapshots Page
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2020-36858
Nagios Log Server < 2.1.6 XSS via Create User, Edit User, & Manage Host Lists Pages
Published 2025-10-30 · Analyzed
5.4EPSS 0.005