5.1

CVSS4.0

CVE-2020-36864 - Nagios XI < 5.7.2 XSS via Dashboard Background Color Setting

Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the background color settings in Dashboards. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:51 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:23 p.m.

5.1

CVSS4.0

CVE-2023-7318 - Nagios XI < 2024R1.0.2 XSS via Core Command Expansion

Nagios XI versions prior to < 2024R1.0.2 are vulnerable to cross-site scripting (XSS) via the Nagios Core Command Expansion page. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:51 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:21 p.m.

5.1

CVSS4.0

CVE-2024-14000 - Nagios XI < 2024R1.1.3 XSS via Capacity Planning Report

Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity Planning Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:51 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:12 p.m.

5.1

CVSS4.0

CVE-2023-7313 - Nagios XI < 5.11.3 XSS via Bulk Modifications

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modifications tool. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:50 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:21 p.m.

5.1

CVSS4.0

CVE-2020-36865 - Nagios XI < 5.7.2 XSS via BPI Config Management

Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the BPI (Business Process Intelligence) component’s Config Management and Edit Config page. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in t…

📅 Published: Oct. 30, 2025, 9:50 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:23 p.m.

5.1

CVSS4.0

CVE-2021-47696 - Nagios XI < 5.8.0 XSS via BPI Config ID Handling

Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via BPI config ID handling. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:49 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:22 p.m.

5.1

CVSS4.0

CVE-2023-7314 - Nagios XI < 5.11.3 XSS via Bandwidth Report

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:49 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:21 p.m.

5.1

CVSS4.0

CVE-2011-10036 - Nagios XI < 2011R1.9 XSS via backend_url JavaScript Link Handler

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of the "backend_url" JavaScript link. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:49 p.m. 🔄 Last Modified: Nov. 6, 2025, 2:32 p.m.

5.1

CVSS4.0

CVE-2011-10039 - Nagios XI < 2011R1.9 XSS via Alert Heatmap Report & “My Reports” Listing

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the Alert Heatmap report and the “My Reports” listing of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of…

📅 Published: Oct. 30, 2025, 9:48 p.m. 🔄 Last Modified: Nov. 6, 2025, 2:55 p.m.

5.1

CVSS4.0

CVE-2021-47699 - Nagios XI < 5.8.7 XSS in Audit Log via Send to NLS Form

Nagios XI versions prior to 5.8.7 are vulnerable to cross-site scripting (XSS) via the Audit Log page’s Send to NLS form. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:48 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:22 p.m.
Total resulsts: 317915
Page 150 of 31,792
« previous page » next page
Filters