VendorsNagiosnagios_xiall versions
Vulnerabilities

Nagios Nagios Xi

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

194CVEs
CVE-2022-29272
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
Published 2022-06-29 · Modified
6.1EPSS 0.041
CVE-2018-15714
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.
Published 2018-11-14 · Modified
6.1EPSS 0.038
CVE-2020-23992
Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request.
Published 2023-08-22 · Modified
6.1EPSS 0.025
CVE-2022-38249
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.
Published 2022-09-07 · Modified
6.1EPSS 0.021
CVE-2022-38248
Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.
Published 2022-09-07 · Modified
6.1EPSS 0.021
CVE-2022-38254
Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.
Published 2022-09-07 · Modified
6.1EPSS 0.021
CVE-2018-20171
An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability.
Published 2018-12-17 · Modified
6.1EPSS 0.016
CVE-2018-20172
An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability.
Published 2018-12-17 · Modified
6.1EPSS 0.016
CVE-2024-54958
Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page.
Published 2025-02-20 · Analyzed
6.1EPSS 0.010
CVE-2024-54959
Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).
Published 2025-02-20 · Analyzed
6.1EPSS 0.010
CVE-2025-56432
A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in user's session via a specially crafted URL. The issue resides in a web component responsible for rendering performance-related data.
Published 2025-08-26 · Modified
6.1EPSS 0.009
CVE-2024-13993
Nagios XI < 2024R1.1.2 Reflected XSS via Login Page on Older Browsers
Published 2025-10-30 · Analyzed
6.1EPSS 0.007
CVE-2024-54957
Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a malicious link that redirects users to an arbitrary external URL without their consent.
Published 2025-02-27 · Analyzed
6.1EPSS 0.006
CVE-2013-10071
Nagios XI < 2012R1.6 Reflected XSS via Dashlet AJAX Load Functionality
Published 2025-10-30 · Analyzed
6.1EPSS 0.005
CVE-2021-47694
Nagios XI < 5.8.6 Core Config Manager (CCM) Reflected XSS via Test Command
Published 2025-10-30 · Analyzed
6.1EPSS 0.005
CVE-2021-38156
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.
Published 2021-09-15 · Modified
5.4EPSS 0.929
CVE-2020-27988
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
Published 2020-11-16 · Modified
5.4EPSS 0.913
CVE-2020-27989
Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).
Published 2020-11-16 · Modified
5.4EPSS 0.344
CVE-2020-27990
Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).
Published 2020-11-16 · Modified
5.4EPSS 0.344
CVE-2020-27991
Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).
Published 2020-11-16 · Modified
5.4EPSS 0.344
CVE-2019-20139
In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin user.
Published 2019-12-30 · Modified
5.4EPSS 0.261
CVE-2018-15713
Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php.
Published 2018-11-14 · Modified
5.4EPSS 0.072
CVE-2018-17146
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin management page.
Published 2019-06-19 · Modified
5.4EPSS 0.036
CVE-2018-10554
An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm parameter, related to components/scheduledreporting; (2) includes/components/xicore/downtime.php, related to the update_pages function; (3) the ajaxhelper.php opts or background parameter; (4) the i[] array parameter to ajax_handler.php; or (5) the deploynotification.php title parameter.
Published 2018-04-30 · Modified
5.4EPSS 0.027
CVE-2023-51072
A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious HTML or JavaScript code via the audio file upload functionality from the Operation Center section. This allows any authenticated user to execute arbitrary JavaScript code on behalf of other users, including the administrators.
Published 2024-02-02 · Modified
5.4EPSS 0.013
CVE-2023-40932
A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.
Published 2023-09-19 · Modified
5.4EPSS 0.009
CVE-2024-42898
A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.
Published 2025-01-09 · Analyzed
5.4EPSS 0.006
CVE-2011-10037
Nagios XI < 2011R1.9 XSS via xiwindow Variables Affecting Permalinks
Published 2025-10-30 · Modified
5.4EPSS 0.006
CVE-2024-14000
Nagios XI < 2024R1.1.3 XSS via Capacity Planning Report
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2024-14001
Nagios XI < 2024R1.1.3 XSS via Executive Summary Report
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2023-7316
Nagios XI < 2024R1 XSS via Graph Explorer
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2023-7318
Nagios XI < 2024R1.0.2 XSS via Core Command Expansion
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2024-13992
Nagios XI < 2024R1.1 XSS via Missing Page / 404
Published 2025-10-31 · Analyzed
5.4EPSS 0.005
CVE-2023-7315
Nagios XI < 5.11.3 XSS via Graph Explorer
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2023-7313
Nagios XI < 5.11.3 XSS via Bulk Modifications
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2023-7314
Nagios XI < 5.11.3 XSS via Bandwidth Report
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2011-10038
Nagios XI < 2011R1.9 XSS via Recurring Downtime Script
Published 2025-10-30 · Analyzed
5.4EPSS 0.004
CVE-2016-15053
Nagios XI < 5.2.4 XSS via “My Reports” Listing
Published 2025-10-30 · Analyzed
5.4EPSS 0.004
CVE-2021-47691
Nagios XI < 5.8.2 Core Config Manager (CCM) XSS via Services Page
Published 2025-10-30 · Analyzed
5.4EPSS 0.004
CVE-2021-47695
Nagios XI < 5.8.0 XSS via My Tools Page
Published 2025-10-30 · Analyzed
5.4EPSS 0.004
← Prev4 / 5Next →