VendorsNetworktocodenautobotany version
Vulnerabilities

Networktocode Nautobot any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2023-25657
Remote code execution in Jinja2 template rendering in Nautobot
Published 2023-02-21 · Modified
9.8EPSS 0.015
CVE-2026-44797
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
Published 2026-05-28 · Analyzed
8.5EPSS 0.004
CVE-2024-34707
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
Published 2024-05-13 · Analyzed
7.5EPSS 0.006
CVE-2024-32979
Reflected Cross-site Scripting potential in all object list views in Nautobot
Published 2024-05-01 · Analyzed
7.5EPSS 0.005
CVE-2023-48705
nautobot has XSS potential in custom links, job buttons, and computed fields
Published 2023-11-22 · Modified
7.1EPSS 0.005
CVE-2026-44798
Nautobot: GitRepository.current_head field should not be writable through REST API
Published 2026-05-28 · Analyzed
7.1EPSS 0.005
CVE-2024-23345
Nautobot has XSS potential in rendered Markdown fields
Published 2024-01-22 · Modified
7.1EPSS 0.004
CVE-2025-49142
Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating
Published 2025-06-10 · Analyzed
7.1EPSS 0.004
CVE-2026-44796
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
Published 2026-05-28 · Analyzed
6.5EPSS 0.006
CVE-2023-46128
Exposure of hashed user passwords via REST API in Nautobot
Published 2023-10-24 · Modified
6.5EPSS 0.005
CVE-2024-36112
Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects
Published 2024-05-28 · Analyzed
6.5EPSS 0.004
CVE-2025-49143
Nautobot may allows uploaded media files to be accessible without authentication
Published 2025-06-10 · Analyzed
6.3EPSS 0.004
CVE-2026-44794
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
Published 2026-05-28 · Analyzed
5.4EPSS 0.003
CVE-2023-50263
Nautobot allows unauthenticated db-file-storage views
Published 2023-12-12 · Modified
5.3EPSS 0.008
CVE-2024-29199
Unauthenticated views may expose information to anonymous users
Published 2024-03-26 · Analyzed
5.3EPSS 0.006
CVE-2023-51649
Nautobot missing object-level permissions enforcement when running Job Buttons
Published 2023-12-22 · Modified
4.3EPSS 0.005
CVE-2026-34203
Nautobot: Management of users via REST API does not apply configured password validators
Published 2026-03-31 · Analyzed
4.3EPSS 0.003