Cacti
84 known vulnerabilities
Top Products
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import sign
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Tra
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regen
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Red
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injectio
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQ
Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request pa
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI t
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflecte
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Tra
Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vu
Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent d
Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request va
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled dat
In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_jso
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP co
A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escapi
A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping o
A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of uninte
A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping o
Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occ
Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_ur
Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] in
auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended acc
Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP c
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private d
Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path
lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrd
include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated user
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-star
Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary
Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML
SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary S
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to in
Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary w
Frequently Asked Questions
How many CVEs affect Cacti?
Cacti has 84 CVE records in our database, including 6 critical and 12 high severity vulnerabilities.
What are the most severe Cacti vulnerabilities?
Cacti has 6 critical severity (CVSS 9.0+) and 12 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Cacti vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Cacti products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Cacti Vulnerabilities
CyberStrike scans your infrastructure for Cacti vulnerabilities and provides real-time remediation guidance.
Get Started