📦

cacti

Vendor: cacti

Actively Exploited 1 CISA KEV List
PoC / Exploits 20 Code Available
Total RCEs 31 Remote Access
Total CVEs 988 Total Indexed
Avg. EPSS 8.78% Exploit Prob.
Latest CVE CVE-2026-40941 Jun 25

Security Vulnerability Index

Page 10 / 99
4.8 CVSS

A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.

EPSS: 1.03%
5.4 CVSS

Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).

EPSS: 1.05%
5.4 CVSS

Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php.

EPSS: 1.01%
5.4 CVSS

Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAME'] to determine a page name.

EPSS: 1.16%
8.8 CVSS

auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database, because the guest user is not considered. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-2313.

EPSS: 2.49%
8.8 CVSS
CVE-2014-4000
RCE Exploit Found

Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object, related to calling unserialize(stripslashes()).

EPSS: 1.67%
6.1 CVSS

Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.

EPSS: 0.99%
4.9 CVSS

Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/passwd.

EPSS: 1.47%
7.2 CVSS

Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.

EPSS: 4.25%
7.2 CVSS

lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php.

EPSS: 3.20%