Cacti records
155 published records for vendor cacti.
Researcher profile
- Entered KEV
- 1 · 0.6%
- Weaponized
- 7 · 4.5%
- Pre-auth RCE
- 23
- With a fix record
- 97.4%
- Median publish → KEV
- 73 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')62
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')42
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')7
- CWE-94 Improper Control of Generation of Code ('Code Injection')5
- CWE-20 Improper Input Validation4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
The weakness classes this vendor ships most often: where to look.
CWEAll records
155 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2022-46169Weaponized | Unauthenticated Command Injectioncacti · cacti · CWE-74 | Critical9.8 | KEV | 99.8% | Dec 5, 2022 |
70This week | CVE-2024-29895Proof of concept | Cacti command injection in cmd_realtime.phpcacti · cacti · CWE-77 | Critical10.0 | — | 98.5% | May 14, 2024 |
66This week | CVE-2023-39361Proof of concept | Unauthenticated SQL Injection in graph_view.php in Cacticacti · cacti · CWE-89 | Critical9.8 | — | 88.8% | Sep 5, 2023 |
57Plan | CVE-2023-49085Weaponized | Cacti SQL Injection vulnerabilitycacti · cacti · CWE-89 | High8.8 | — | 74.5% | Dec 22, 2023 |
57Plan | CVE-2020-8813Proof of concept | graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest cacti · cacti · CWE-78 | High8.8 | — | 74.0% | Feb 21, 2020 |
55Plan | CVE-2023-51448No exploit | SQL Injection vulnerability when managing SNMP Notification Receiverscacti · cacti · CWE-89 | High8.8 | — | 67.3% | Dec 22, 2023 |
54Plan | CVE-2020-14295Weaponized | A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter.cacti · cacti · CWE-89 | High7.2 | — | 86.3% | Jun 17, 2020 |
54Plan | CVE-2024-25641Weaponized | Cacti RCE vulnerability when importing packagescacti · cacti · CWE-20 | High7.2 | — | 86.3% | May 14, 2024 |
54Plan | CVE-2023-39362Proof of concept | Authenticated command injection in SNMP options of a Devicecacti · cacti · CWE-78 | High7.2 | — | 85.4% | Sep 5, 2023 |
54Plan | CVE-2023-49084Weaponized | Local File Inclusion (RCE) in Cacticacti · cacti · CWE-98 | High8.8 | — | 64.4% | Dec 21, 2023 |
50Plan | CVE-2025-24367Weaponized | Cacti allows Arbitrary File Creation leading to RCEcacti · cacti · CWE-144 | High8.7 | — | 54.0% | Jan 27, 2025 |
47Plan | CVE-2024-54146No exploit | Cacti has a SQL Injection vulnerability when view host templatecacti · cacti · CWE-89 | High8.8 | — | 41.0% | Jan 27, 2025 |
46Plan | CVE-2020-7237No exploit | Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_acacti · cacti · CWE-78 | High8.8 | — | 37.1% | Jan 20, 2020 |
43Plan | CVE-2024-43364No exploit | Stored Cross-site Scripting (XSS) when creating external links in Cacticacti · cacti · CWE-79 | High8.2 | — | 37.9% | Oct 7, 2024 |
43Plan | CVE-2024-31445No exploit | SQL Injection vulnerability in automation_get_new_graphs_sqlcacti · cacti · CWE-89 | High8.8 | — | 26.2% | May 14, 2024 |
40Plan | CVE-2024-43365No exploit | Stored Cross-site Scripting (XSS) when creating external links in Cacticacti · cacti · CWE-79 | High8.2 | — | 25.1% | Oct 7, 2024 |
40Plan | CVE-2022-0730No exploit | Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.cacti · cacti · CWE-287 | Critical9.8 | — | 3.5% | Mar 3, 2022 |
40Plan | CVE-2017-12065No exploit | spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end pacacti · cacti | Critical9.8 | — | 2.9% | Aug 1, 2017 |
39Monitor | CVE-2024-43363Proof of concept | Remote code execution via Log Poisoning in Cacticacti · cacti · CWE-94 | High7.2 | — | 35.6% | Oct 7, 2024 |
39Monitor | CVE-2009-4112Proof of concept | Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux -cacti · cacti · CWE-264 | Critical9.0 | — | 11.5% | Nov 30, 2009 |
39Monitor | CVE-2026-39938Proof of concept | Cacti: Unauthenticated RCE on Graph Imagecacti · cacti · CWE-22 | Critical9.8 | — | 0.7% | Jun 24, 2026 |
39Monitor | CVE-2026-39893No exploit | Cacti: Pre-authentication SQL injection via rfilter RLIKE clause in graph_view.phpcacti · cacti · CWE-89 | Critical9.8 | — | 0.7% | Jun 24, 2026 |
39Monitor | CVE-2026-39955No exploit | Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.phpcacti · cacti · CWE-89 | Critical9.8 | — | 0.6% | Jun 24, 2026 |
39Monitor | CVE-2025-26520No exploit | Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter.cacti · cacti · CWE-89 | Critical9.8 | — | 0.5% | Feb 12, 2025 |
37Monitor | CVE-2026-39948No exploit | Cacti has SQL Injection via rfilter parameter in RLIKE clausescacti · cacti · CWE-89 | Critical9.3 | — | 0.8% | Jun 24, 2026 |
- CVE-2022-4616999Now
Unauthenticated Command Injection
CriticalCVSS 9.8KEVWeaponizedEPSS 100%cacti · cactiDec 5, 2022
- CVE-2024-2989570This week
Cacti command injection in cmd_realtime.php
CriticalCVSS 10.0Proof of conceptEPSS 98%cacti · cactiMay 14, 2024
- CVE-2023-3936166This week
Unauthenticated SQL Injection in graph_view.php in Cacti
CriticalCVSS 9.8Proof of conceptEPSS 89%cacti · cactiSep 5, 2023
- CVE-2023-4908557Plan
Cacti SQL Injection vulnerability
HighCVSS 8.8WeaponizedEPSS 74%cacti · cactiDec 22, 2023
- CVE-2020-881357Plan
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest
HighCVSS 8.8Proof of conceptEPSS 74%cacti · cactiFeb 21, 2020
- CVE-2023-5144855Plan
SQL Injection vulnerability when managing SNMP Notification Receivers
HighCVSS 8.8No exploitEPSS 67%cacti · cactiDec 22, 2023
- CVE-2020-1429554Plan
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter.
HighCVSS 7.2WeaponizedEPSS 86%cacti · cactiJun 17, 2020
- CVE-2024-2564154Plan
Cacti RCE vulnerability when importing packages
HighCVSS 7.2WeaponizedEPSS 86%cacti · cactiMay 14, 2024
- CVE-2023-3936254Plan
Authenticated command injection in SNMP options of a Device
HighCVSS 7.2Proof of conceptEPSS 85%cacti · cactiSep 5, 2023
- CVE-2023-4908454Plan
Local File Inclusion (RCE) in Cacti
HighCVSS 8.8WeaponizedEPSS 64%cacti · cactiDec 21, 2023
- CVE-2025-2436750Plan
Cacti allows Arbitrary File Creation leading to RCE
HighCVSS 8.7WeaponizedEPSS 54%cacti · cactiJan 27, 2025
- CVE-2024-5414647Plan
Cacti has a SQL Injection vulnerability when view host template
HighCVSS 8.8No exploitEPSS 41%cacti · cactiJan 27, 2025
- CVE-2020-723746Plan
Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_a
HighCVSS 8.8No exploitEPSS 37%cacti · cactiJan 20, 2020
- CVE-2024-4336443Plan
Stored Cross-site Scripting (XSS) when creating external links in Cacti
HighCVSS 8.2No exploitEPSS 38%cacti · cactiOct 7, 2024
- CVE-2024-3144543Plan
SQL Injection vulnerability in automation_get_new_graphs_sql
HighCVSS 8.8No exploitEPSS 26%cacti · cactiMay 14, 2024
- CVE-2024-4336540Plan
Stored Cross-site Scripting (XSS) when creating external links in Cacti
HighCVSS 8.2No exploitEPSS 25%cacti · cactiOct 7, 2024
- CVE-2022-073040Plan
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
CriticalCVSS 9.8No exploitEPSS 3%cacti · cactiMar 3, 2022
- CVE-2017-1206540Plan
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end pa
CriticalCVSS 9.8No exploitEPSS 3%cacti · cactiAug 1, 2017
- CVE-2024-4336339Monitor
Remote code execution via Log Poisoning in Cacti
HighCVSS 7.2Proof of conceptEPSS 36%cacti · cactiOct 7, 2024
- CVE-2009-411239Monitor
Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux -
CriticalCVSS 9.0Proof of conceptEPSS 11%cacti · cactiNov 30, 2009
- CVE-2026-3993839Monitor
Cacti: Unauthenticated RCE on Graph Image
CriticalCVSS 9.8Proof of conceptEPSS 1%cacti · cactiJun 24, 2026
- CVE-2026-3989339Monitor
Cacti: Pre-authentication SQL injection via rfilter RLIKE clause in graph_view.php
CriticalCVSS 9.8No exploitEPSS 1%cacti · cactiJun 24, 2026
- CVE-2026-3995539Monitor
Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php
CriticalCVSS 9.8No exploitEPSS 1%cacti · cactiJun 24, 2026
- CVE-2025-2652039Monitor
Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter.
CriticalCVSS 9.8No exploitEPSS 0%cacti · cactiFeb 12, 2025
- CVE-2026-3994837Monitor
Cacti has SQL Injection via rfilter parameter in RLIKE clauses
CriticalCVSS 9.3No exploitEPSS 1%cacti · cactiJun 24, 2026