📦 Cacti

by Cacti

🔍 What is Cacti?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-22604

CRITICAL CVSS 9.1 Jan 27, 2025

CVE-2025-22604 is a command injection vulnerability in Cacti's SNMP result parser that allows authenticated users to execute arbitrary system commands. The vulnerability affects Cacti versions before ...

CVE-2024-25641

CRITICAL CVSS 9.1 May 14, 2024

CVE-2024-25641 is an arbitrary file write vulnerability in Cacti's Package Import feature that allows authenticated users with 'Import Templates' permission to write arbitrary files to the web server,...

CVE-2023-39361

CRITICAL CVSS 9.8 Sep 5, 2023

CVE-2023-39361 is a critical SQL injection vulnerability in Cacti's graph_view.php that allows unauthenticated attackers to execute arbitrary SQL commands. Since guest users can access this endpoint w...

CVE-2022-0730

CRITICAL CVSS 9.8 Mar 3, 2022

CVE-2022-0730 is an authentication bypass vulnerability in Cacti that allows attackers to gain unauthorized access under specific LDAP configurations. The vulnerability affects Cacti systems using LDA...

CVE-2025-66399

HIGH CVSS 8.8 Dec 2, 2025

This vulnerability allows authenticated Cacti users to inject malicious SNMP community strings containing control characters like newlines. When these strings are used in backend SNMP operations, they...

CVE-2005-10004

HIGH CVSS 8.8 Aug 30, 2025

This vulnerability allows authenticated users to execute arbitrary shell commands on Cacti servers through improper input handling in the graph_view.php script. Attackers can compromise system integri...

CVE-2025-26520

HIGH CVSS 7.6 Feb 12, 2025

CVE-2025-26520 is an SQL injection vulnerability in Cacti's host_templates.php file via the graph_template parameter. This allows attackers to execute arbitrary SQL commands on the database. All Cacti...

CVE-2025-24367

HIGH CVSS 8.8 Jan 27, 2025

An authenticated Cacti user can abuse graph creation functionality to write arbitrary PHP files to the web root, leading to remote code execution on the server. This affects all Cacti installations wi...

CVE-2025-24368

HIGH CVSS 7.5 Jan 27, 2025

This SQL injection vulnerability in Cacti allows attackers to manipulate database queries through the automation_tree_rules.php interface. Attackers could potentially read, modify, or delete data from...

CVE-2024-54146

HIGH CVSS 7.6 Jan 27, 2025

Cacti versions before 1.2.29 contain a SQL injection vulnerability in the host_templates.php template function via the graph_template parameter. This allows authenticated attackers to execute arbitrar...

CVE-2024-43362

HIGH CVSS 7.3 Oct 7, 2024

This stored XSS vulnerability in Cacti allows authenticated users with external link creation privileges to inject malicious scripts into web pages. When other users view pages containing these manipu...

CVE-2024-31459

HIGH CVSS 8.0 May 14, 2024

CVE-2024-31459 is a critical vulnerability in Cacti monitoring software that allows remote code execution through a combination of SQL injection and file inclusion flaws. Attackers can exploit this to...

CVE-2024-31445

HIGH CVSS 8.8 May 14, 2024

This SQL injection vulnerability in Cacti allows authenticated users to execute arbitrary SQL commands, potentially leading to privilege escalation and remote code execution. It affects all Cacti inst...

CVE-2023-49084

HIGH CVSS 8.0 Dec 21, 2023

This CVE-2023-49084 vulnerability in Cacti allows authenticated users to perform SQL injection and arbitrary code execution on the server through the link.php component. Attackers can exploit insuffic...

CVE-2023-31132

HIGH CVSS 7.8 Sep 5, 2023

This CVE describes a privilege escalation vulnerability in Cacti where low-privileged Windows users can create arbitrary PHP files in web directories and execute them with SYSTEM privileges. Affected ...

CVE-2023-39357

HIGH CVSS 8.8 Sep 5, 2023

CVE-2023-39357 is a SQL injection vulnerability in Cacti's sql_save function that allows authenticated users to execute arbitrary SQL commands. This can lead to privilege escalation and remote code ex...

CVE-2023-39362

HIGH CVSS 7.2 Sep 5, 2023

This vulnerability allows authenticated privileged users in Cacti 1.2.24 to perform command injection through SNMP device configuration, leading to remote code execution on the underlying server. The ...

CVE-2023-39359

HIGH CVSS 8.8 Sep 5, 2023

An authenticated SQL injection vulnerability in Cacti allows authenticated users to escalate privileges and execute arbitrary code remotely. The vulnerability affects Cacti versions before 1.2.25 thro...

CVE-2023-37543

HIGH CVSS 7.5 Aug 10, 2023

CVE-2023-37543 is an Insecure Direct Object Reference (IDOR) vulnerability in Cacti that allows attackers to access any monitoring graph by manipulating the local_graph_id parameter in graph_xport.php...

CVE-2024-54145

MEDIUM CVSS 6.3 Jan 27, 2025

CVE-2024-54145 is a SQL injection vulnerability in Cacti's automation_devices.php file that allows attackers to execute arbitrary SQL commands through the network parameter. This affects all Cacti adm...

CVE-2024-45598

MEDIUM CVSS 6.0 Jan 27, 2025

This vulnerability in Cacti allows administrators to read arbitrary local files on the server by manipulating the Poller Standard Error Log Path parameter and accessing the Logs tab. The issue affects...

CVE-2024-43364

MEDIUM CVSS 5.7 Oct 7, 2024

This stored XSS vulnerability in Cacti allows authenticated users with external link creation privileges to inject malicious scripts via the title parameter. When other users view the affected page, t...

CVE-2024-31443

MEDIUM CVSS 5.7 May 14, 2024

CVE-2024-31443 is a cross-site scripting (XSS) vulnerability in Cacti's data query functionality. Attackers can inject malicious scripts that execute in users' browsers when viewing certain pages. Thi...

CVE-2024-29894

MEDIUM CVSS 5.4 May 14, 2024

CVE-2024-29894 is a residual cross-site scripting (XSS) vulnerability in Cacti monitoring software that allows attackers to inject malicious JavaScript via unescaped PHP variables. This could enable i...