VendorsNagiosnagios_xiall versions
Vulnerabilities

Nagios Nagios Xi

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

194CVEs
CVE-2018-15710
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
Published 2018-11-14 · Modified
7.82 PoCEPSS 0.441
CVE-2020-5796
Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users being able to write to and execute arbitrary PHP code with root privileges.
Published 2020-11-13 · Modified
7.8EPSS 0.020
CVE-2019-9166
Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xiconfig.php.
Published 2019-03-28 · Modified
7.8EPSS 0.012
CVE-2021-37347
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.
Published 2021-08-13 · Modified
7.8EPSS 0.008
CVE-2021-37349
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database.
Published 2021-08-13 · Modified
7.8EPSS 0.007
CVE-2021-40343
An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios user to elevate their privileges to the root user.
Published 2021-10-26 · Modified
7.8EPSS 0.007
CVE-2021-37345
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.
Published 2021-08-13 · Modified
7.8EPSS 0.006
CVE-2013-6875
SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.
Published 2013-11-26 · Modified
7.51 PoCEPSS 0.032
CVE-2021-37348
Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.
Published 2021-08-13 · Modified
7.5EPSS 0.028
CVE-2025-67254
NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.
Published 2025-12-29 · Analyzed
7.5EPSS 0.020
CVE-2011-10035
Nagios XI < 2011R1.9 Race Conditions in Crontab Install Scripts LPE
Published 2025-10-30 · Analyzed
7.3EPSS 0.002
CVE-2021-40344
An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary extensions as long as the MIME type corresponds to an image. Therefore it is possible to upload a crafted PHP script to achieve remote command execution.
Published 2021-10-26 · Modified
7.2EPSS 0.648
CVE-2020-5792
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code with the privileges of the apache user.
Published 2020-10-20 · Modified
7.2EPSS 0.595
CVE-2021-3277
Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.
Published 2021-06-07 · Modified
7.2EPSS 0.546
CVE-2018-10735
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
Published 2018-05-16 · Modified
7.2EPSS 0.421
CVE-2018-10736
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
Published 2018-05-16 · Modified
7.2EPSS 0.421
CVE-2018-10737
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.
Published 2018-05-16 · Modified
7.2EPSS 0.421
CVE-2018-10738
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.
Published 2018-05-16 · Modified
7.2EPSS 0.421
CVE-2020-22427
NagiosXI 5.6.11 is affected by a remote code execution (RCE) vulnerability. An authenticated nagiosadmin user can inject additional commands into a request. NOTE: the vendor disputes whether the CVE and its references are actionable because all technical details are omitted, and the only option is to pay for a subscription service where technical details may be disclosed at an unspecified later time
Published 2021-02-15 · Modified
7.2EPSS 0.143
CVE-2023-40934
A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.
Published 2023-09-19 · Modified
7.2EPSS 0.024
CVE-2013-10072
Nagios XI < 2012R1.6 Auto-Discovery Missing Authorization
Published 2025-10-30 · Analyzed
7.2EPSS 0.007
CVE-2024-14002
Nagios XI < 2024R1.1.4 Authenticated Local File Inclusion via NagVis
Published 2025-10-30 · Analyzed
7.1EPSS 0.012
CVE-2025-34283
Nagios XI < 2024R1.4.2 API Key Disclosure via Neptune Themes
Published 2025-10-30 · Analyzed
7.1EPSS 0.010
CVE-2020-36862
Nagios XI < 5.6.11 Unauthenticated XSS and SSRF via Highcharts
Published 2025-10-30 · Analyzed
6.9EPSS 0.006
CVE-2018-10553
An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginning with index.php?xiwindow=./ and config/?xiwindow=../ substrings.
Published 2018-04-30 · Modified
6.5EPSS 0.390
CVE-2023-40931
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php
Published 2023-09-19 · Modified
6.5EPSS 0.119
CVE-2021-37223
Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI application. Due to lack of input sanitisation, the target page can be replaced with an SSRF payload to access internal resources or disclose local system files.
Published 2021-10-05 · Modified
6.5EPSS 0.050
CVE-2022-29269
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
Published 2022-06-29 · Modified
6.5EPSS 0.030
CVE-2020-5790
Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
Published 2020-10-20 · Modified
6.5EPSS 0.023
CVE-2022-29271
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
Published 2022-06-29 · Modified
6.5EPSS 0.020
CVE-2024-54961
Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users.
Published 2025-02-20 · Analyzed
6.5EPSS 0.016
CVE-2024-54960
A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.
Published 2025-02-20 · Analyzed
6.5EPSS 0.014
CVE-2024-13998
Nagios XI < 2024R1.1.3 API Keys & Hashed Passwords Authenticated Information Disclosure
Published 2025-11-03 · Analyzed
6.5EPSS 0.010
CVE-2021-25299
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.
Published 2021-02-15 · Modified
6.1EPSS 0.978
CVE-2018-15712
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.
Published 2018-11-14 · Modified
6.1EPSS 0.486
CVE-2020-15902
Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.
Published 2020-07-22 · Modified
6.1EPSS 0.351
CVE-2021-26023
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.
Published 2021-02-03 · Modified
6.1EPSS 0.252
CVE-2019-9167
Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter.
Published 2019-03-28 · Modified
6.1EPSS 0.217
CVE-2021-33179
The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload.
Published 2021-10-14 · Modified
6.1EPSS 0.117
CVE-2021-37352
An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.
Published 2021-08-13 · Modified
6.1EPSS 0.061
← Prev3 / 5Next →