📦 Netbox

by Netbox

🔍 What is Netbox?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-33796

CRITICAL CVSS 9.1 May 24, 2023

A disputed vulnerability in Netbox v3.5.1 reportedly allows unauthenticated attackers to query the GraphQL database, potentially exposing sensitive data. The vendor disputes the severity, stating only...

CVE-2025-69848

MEDIUM CVSS 5.4 Feb 3, 2026

A reflected cross-site scripting (XSS) vulnerability in NetBox allows attackers to inject malicious scripts into error messages when delete operations fail. This affects NetBox versions 2.11.0 through...

CVE-2024-56915

MEDIUM CVSS 6.5 Jun 26, 2025

This vulnerability allows attackers to inject malicious scripts into Netbox's RSS feed widget, which are then executed in users' browsers when viewing the widget. It affects Netbox Community v4.1.7 in...

CVE-2024-47226

MEDIUM CVSS 5.4 Sep 22, 2024

A stored XSS vulnerability exists in NetBox 4.1.0's configuration history feature where authenticated users can inject malicious JavaScript/HTML into the 'Top banner' field. This allows attackers to e...

CVE-2024-40737

MEDIUM CVSS 6.1 Jul 9, 2024

A stored cross-site scripting (XSS) vulnerability in NetBox v4.0.3 allows authenticated attackers to inject malicious scripts into the Name parameter when adding console ports. This vulnerability affe...

CVE-2024-40739

MEDIUM CVSS 6.1 Jul 9, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in NetBox v4.0.3 where attackers can inject malicious scripts into the Name parameter when adding power feeds. This allows execution of ar...

CVE-2024-40741

MEDIUM CVSS 6.1 Jul 9, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in NetBox v4.0.3 that allows attackers to inject malicious scripts into the circuit ID parameter. When exploited, this enables execution o...

CVE-2024-40727

MEDIUM CVSS 6.1 Jul 9, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in NetBox v4.0.3 where attackers can inject malicious scripts into the Name parameter when adding console server ports. This allows execut...

CVE-2024-40729

MEDIUM CVSS 6.1 Jul 9, 2024

This cross-site scripting (XSS) vulnerability in NetBox v4.0.3 allows attackers to inject malicious scripts into the Name parameter when adding interfaces, which could execute arbitrary code in victim...

CVE-2024-40731

MEDIUM CVSS 6.1 Jul 9, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in NetBox v4.0.3 that allows attackers to inject malicious scripts into the Name parameter when editing rear ports. This affects all NetBo...

CVE-2024-40733

MEDIUM CVSS 6.1 Jul 9, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in NetBox v4.0.3 that allows attackers to inject malicious scripts into the Name parameter when editing front ports. This affects any NetB...

CVE-2024-40735

MEDIUM CVSS 6.1 Jul 9, 2024

A stored cross-site scripting (XSS) vulnerability in NetBox v4.0.3 allows authenticated attackers to inject malicious scripts into the Name parameter of power outlet edit forms. When other users view ...

CVE-2024-38972

MEDIUM CVSS 6.1 Jul 9, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in NetBox v4.0.3 that allows attackers to inject malicious scripts into the Name parameter when adding power ports. Attackers can execute ...