Cacti

Cacti

140 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 29.01.2026 00:00:00
  • Zuletzt bearbeitet 02.02.2026 23:15:59

A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid format is uploaded, the application reflects the submitted filename back into an error popup without proper sanitization. As a resu...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 02.12.2025 17:57:11
  • Zuletzt bearbeitet 05.12.2025 18:57:11

Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configuration functionality. An authenticated Cacti user can supply crafted SNMP community strings containing co...

Exploit
  • EPSS 54%
  • Veröffentlicht 30.08.2025 13:45:16
  • Zuletzt bearbeitet 26.12.2025 16:42:27

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rende...

  • EPSS 0.12%
  • Veröffentlicht 12.02.2025 07:15:08
  • Zuletzt bearbeitet 12.02.2025 07:15:08

Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists because of an incomplete fix for CVE-2024-54146.

Exploit
  • EPSS 55.97%
  • Veröffentlicht 27.01.2025 18:15:42
  • Zuletzt bearbeitet 03.11.2025 22:18:40

Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execu...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 27.01.2025 18:15:42
  • Zuletzt bearbeitet 03.11.2025 22:18:40

Cacti is an open source performance and fault management framework. Some of the data stored in automation_tree_rules.php is not thoroughly checked and is used to concatenate the SQL statement in build_rule_item_filter() function from lib/api_automati...

Exploit
  • EPSS 54.21%
  • Veröffentlicht 27.01.2025 17:15:17
  • Zuletzt bearbeitet 03.11.2025 21:19:13

Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject malformed OIDs in the response. When processed by ss_net_snmp_disk_io() or ss_net_snmp_disk_bytes(), a ...

Exploit
  • EPSS 0.74%
  • Veröffentlicht 27.01.2025 17:15:16
  • Zuletzt bearbeitet 03.11.2025 21:17:48

Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the get_discovery_results function of automation_devices.php using the network parameter. This vulnerability is fixed in 1.2.29.

Exploit
  • EPSS 1.04%
  • Veröffentlicht 27.01.2025 17:15:16
  • Zuletzt bearbeitet 04.03.2025 14:45:17

Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the template function of host_templates.php using the graph_template parameter. This vulnerability is fixed in 1.2.29.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 27.01.2025 16:15:31
  • Zuletzt bearbeitet 03.11.2025 21:16:21

Cacti is an open source performance and fault management framework. Prior to 1.2.29, an administrator can change the `Poller Standard Error Log Path` parameter in either Installation Step 5 or in Configuration->Settings->Paths tab to a local file ins...