VendorsNagiosnagios_xiany version
Vulnerabilities

Nagios Nagios Xi any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

148CVEs
CVE-2025-34283
Nagios XI < 2024R1.4.2 API Key Disclosure via Neptune Themes
Published 2025-10-30 · Analyzed
7.1EPSS 0.010
CVE-2020-36862
Nagios XI < 5.6.11 Unauthenticated XSS and SSRF via Highcharts
Published 2025-10-30 · Analyzed
6.9EPSS 0.006
CVE-2023-40931
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php
Published 2023-09-19 · Modified
6.5EPSS 0.119
CVE-2021-37223
Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI application. Due to lack of input sanitisation, the target page can be replaced with an SSRF payload to access internal resources or disclose local system files.
Published 2021-10-05 · Modified
6.5EPSS 0.050
CVE-2022-29269
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
Published 2022-06-29 · Modified
6.5EPSS 0.030
CVE-2022-29271
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
Published 2022-06-29 · Modified
6.5EPSS 0.020
CVE-2024-13998
Nagios XI < 2024R1.1.3 API Keys & Hashed Passwords Authenticated Information Disclosure
Published 2025-11-03 · Analyzed
6.5EPSS 0.010
CVE-2020-15902
Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.
Published 2020-07-22 · Modified
6.1EPSS 0.351
CVE-2019-9167
Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter.
Published 2019-03-28 · Modified
6.1EPSS 0.217
CVE-2021-33179
The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload.
Published 2021-10-14 · Modified
6.1EPSS 0.117
CVE-2021-37352
An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.
Published 2021-08-13 · Modified
6.1EPSS 0.061
CVE-2022-29272
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
Published 2022-06-29 · Modified
6.1EPSS 0.041
CVE-2022-38248
Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.
Published 2022-09-07 · Modified
6.1EPSS 0.021
CVE-2022-38254
Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.
Published 2022-09-07 · Modified
6.1EPSS 0.021
CVE-2018-20171
An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability.
Published 2018-12-17 · Modified
6.1EPSS 0.016
CVE-2018-20172
An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability.
Published 2018-12-17 · Modified
6.1EPSS 0.016
CVE-2024-13993
Nagios XI < 2024R1.1.2 Reflected XSS via Login Page on Older Browsers
Published 2025-10-30 · Analyzed
6.1EPSS 0.007
CVE-2013-10071
Nagios XI < 2012R1.6 Reflected XSS via Dashlet AJAX Load Functionality
Published 2025-10-30 · Analyzed
6.1EPSS 0.005
CVE-2021-47694
Nagios XI < 5.8.6 Core Config Manager (CCM) Reflected XSS via Test Command
Published 2025-10-30 · Analyzed
6.1EPSS 0.005
CVE-2021-38156
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.
Published 2021-09-15 · Modified
5.4EPSS 0.929
CVE-2020-27988
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
Published 2020-11-16 · Modified
5.4EPSS 0.913
CVE-2020-27989
Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).
Published 2020-11-16 · Modified
5.4EPSS 0.344
CVE-2020-27990
Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).
Published 2020-11-16 · Modified
5.4EPSS 0.344
CVE-2020-27991
Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).
Published 2020-11-16 · Modified
5.4EPSS 0.344
CVE-2018-17146
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin management page.
Published 2019-06-19 · Modified
5.4EPSS 0.036
CVE-2023-51072
A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious HTML or JavaScript code via the audio file upload functionality from the Operation Center section. This allows any authenticated user to execute arbitrary JavaScript code on behalf of other users, including the administrators.
Published 2024-02-02 · Modified
5.4EPSS 0.013
CVE-2023-40932
A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.
Published 2023-09-19 · Modified
5.4EPSS 0.009
CVE-2011-10037
Nagios XI < 2011R1.9 XSS via xiwindow Variables Affecting Permalinks
Published 2025-10-30 · Modified
5.4EPSS 0.006
CVE-2024-14000
Nagios XI < 2024R1.1.3 XSS via Capacity Planning Report
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2024-14001
Nagios XI < 2024R1.1.3 XSS via Executive Summary Report
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2024-13992
Nagios XI < 2024R1.1 XSS via Missing Page / 404
Published 2025-10-31 · Analyzed
5.4EPSS 0.005
CVE-2023-7318
Nagios XI < 2024R1.0.2 XSS via Core Command Expansion
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2023-7316
Nagios XI < 2024R1 XSS via Graph Explorer
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2023-7315
Nagios XI < 5.11.3 XSS via Graph Explorer
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2023-7313
Nagios XI < 5.11.3 XSS via Bulk Modifications
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2023-7314
Nagios XI < 5.11.3 XSS via Bandwidth Report
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2011-10038
Nagios XI < 2011R1.9 XSS via Recurring Downtime Script
Published 2025-10-30 · Analyzed
5.4EPSS 0.004
CVE-2016-15053
Nagios XI < 5.2.4 XSS via “My Reports” Listing
Published 2025-10-30 · Analyzed
5.4EPSS 0.004
CVE-2021-47691
Nagios XI < 5.8.2 Core Config Manager (CCM) XSS via Services Page
Published 2025-10-30 · Analyzed
5.4EPSS 0.004
CVE-2021-47695
Nagios XI < 5.8.0 XSS via My Tools Page
Published 2025-10-30 · Analyzed
5.4EPSS 0.004
← Prev3 / 4Next →