Nagios Nagios

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Nagios product.

RSS Feeds for Nagios security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Nagios products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Nagios Sorted by Most Security Vulnerabilities since 2018

Nagios Xi102 vulnerabilities

Nagios Fusion12 vulnerabilities

Nagios8 vulnerabilities

Nagios Log Server6 vulnerabilities

Nagios Core4 vulnerabilities

Nagios Incident Manager3 vulnerabilities

Nagios Cross Platform Agent2 vulnerabilities

Nagios Network Analyzer2 vulnerabilities

Nagios Network Analyzer2 vulnerabilities

Nagios Xi Docker Wizard1 vulnerability

Nagios Xi Switch Wizard1 vulnerability

Nagios Ndoutils1 vulnerability

Known Exploited Nagios Vulnerabilities

The following Nagios vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Nagios XI OS Command Injection Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVE-2021-25296 Exploit Probability: 93.5%
January 18, 2022
Nagios XI OS Command Injection Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVE-2021-25297 Exploit Probability: 51.0%
January 18, 2022
Nagios XI OS Command Injection Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVE-2021-25298 Exploit Probability: 77.1%
January 18, 2022
Nagios XI Remote Code Execution Vulnerability The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user
CVE-2019-15949 Exploit Probability: 87.2%
November 3, 2021

Of the known exploited vulnerabilities above, 2 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 2 known exploited Nagios vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

By the Year

In 2025 there have been 7 vulnerabilities in Nagios. Last year, in 2024 Nagios had 6 security vulnerabilities published. That is, 1 more vulnerability have already been reported in 2025 as compared to last year.




Year Vulnerabilities Average Score
2025 7 0.00
2024 6 6.95
2023 7 7.66
2022 11 6.11
2021 49 8.09
2020 22 6.72
2019 15 7.99
2018 25 7.15

It may take a day or so for new Nagios vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Nagios Security Vulnerabilities

Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1

CVE-2025-29471 - April 15, 2025

Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.

A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3

CVE-2025-28131 - April 01, 2025

A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due to improper authorization enforcement, enabling unauthorized modifications that compromise system integrity and availability.

A session management flaw in Nagios Network Analyzer 2024R1.0.3

CVE-2025-28132 - April 01, 2025

A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized access and account takeover. This occurs due to insufficient session expiration, where session tokens remain valid beyond logout, allowing an attacker to impersonate users and perform actions on their behalf.

Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page

CVE-2024-54958 - February 20, 2025

Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page.

Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component

CVE-2024-54959 - February 20, 2025

Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).

Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which

CVE-2024-54961 - February 20, 2025

Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users.

A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4

CVE-2024-42898 - January 09, 2025

A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.

Nagios NDOUtils before 2.1.4

CVE-2024-43199 7.8 - High - August 07, 2024

Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user.

Incorrect Permission Assignment for Critical Resource

An issue with the Autodiscover component in Nagios XI 2024R1.01

CVE-2024-33775 - May 01, 2024

An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

SQL Injection vulnerability in Nagios XI 2024R1.01

CVE-2024-24401 - February 26, 2024

SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.

An issue in Nagios XI 2024R1.01

CVE-2024-24402 9.8 - Critical - February 26, 2024

An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.

A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1

CVE-2023-51072 5.4 - Medium - February 02, 2024

A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious HTML or JavaScript code via the audio file upload functionality from the Operation Center section. This allows any authenticated user to execute arbitrary JavaScript code on behalf of other users, including the administrators.

XSS

DOM-based Cross Site Scripting (XSS vulnerability in 'Tail Event Logs' functionality in Nagios Nagios Cross-Platform Agent (NCPA) before 2.4.0

CVE-2021-43584 4.8 - Medium - January 24, 2024

DOM-based Cross Site Scripting (XSS vulnerability in 'Tail Event Logs' functionality in Nagios Nagios Cross-Platform Agent (NCPA) before 2.4.0 allows attackers to run arbitrary code via the name element when filtering for a log.

XSS

Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability

CVE-2023-48084 9.8 - Critical - December 14, 2023

Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.

SQL Injection

Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability

CVE-2023-48085 9.8 - Critical - December 14, 2023

Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.

A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1

CVE-2023-40931 6.5 - Medium - September 19, 2023

A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php

SQL Injection

A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below

CVE-2023-40932 5.4 - Medium - September 19, 2023

A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.

XSS

A SQL injection vulnerability in Nagios XI v5.11.1 and below

CVE-2023-40933 8.8 - High - September 19, 2023

A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.

SQL Injection

A SQL injection vulnerability in Nagios XI 5.11.1 and below

CVE-2023-40934 7.2 - High - September 19, 2023

A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.

SQL Injection

Cross Site Scripting (XSS) in Nagios XI 5.7.1

CVE-2020-23992 6.1 - Medium - August 22, 2023

Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request.

XSS

A vulnerability classified as problematic was found in Nagios NCPA

CVE-2021-4285 6.1 - Medium - December 27, 2022

A vulnerability classified as problematic was found in Nagios NCPA. This vulnerability affects unknown code of the file agent/listener/templates/tail.html. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 2.4.0 is able to address this issue. The name of the patch is 5abbcd7aa26e0fc815e6b2b0ffe1c15ef3e8fab5. It is recommended to upgrade the affected component. VDB-216874 is the identifier assigned to this vulnerability.

XSS

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability

CVE-2022-38247 4.8 - Medium - September 07, 2022

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel.

XSS

Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.

CVE-2022-38248 6.1 - Medium - September 07, 2022

Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.

XSS

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability

CVE-2022-38249 6.1 - Medium - September 07, 2022

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.

XSS

Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability

CVE-2022-38250 9.8 - Critical - September 07, 2022

Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.

SQL Injection

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability

CVE-2022-38251 4.8 - Medium - September 07, 2022

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel.

XSS

Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability

CVE-2022-38254 6.1 - Medium - September 07, 2022

Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.

XSS

In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags

CVE-2022-29269 6.5 - Medium - June 29, 2022

In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.

XSS

In Nagios XI through 5.8.5

CVE-2022-29270 4.3 - Medium - June 29, 2022

In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.

Missing Authentication for Critical Function

In Nagios XI through 5.8.5

CVE-2022-29271 6.5 - Medium - June 29, 2022

In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.

AuthZ

In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function

CVE-2022-29272 6.1 - Medium - June 29, 2022

In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.

Open Redirect

An issue was discovered in Nagios XI 5.8.5

CVE-2021-40344 7.2 - High - October 26, 2021

An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary extensions as long as the MIME type corresponds to an image. Therefore it is possible to upload a crafted PHP script to achieve remote command execution.

Unrestricted File Upload

An issue was discovered in Nagios XI 5.8.5

CVE-2021-40345 7.2 - High - October 26, 2021

An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attacker to execute system commands.

Command Injection

An issue was discovered in Nagios XI 5.8.5

CVE-2021-40343 7.8 - High - October 26, 2021

An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios user to elevate their privileges to the root user.

Incorrect Permission Assignment for Critical Resource

The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection

CVE-2021-33177 8.8 - High - October 14, 2021

The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation requires the malicious actor to be authenticated to the vulnerable system, but once authenticated they would be able to execute arbitrary sql queries.

SQL Injection

The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path traversal vulnerability

CVE-2021-33178 6.5 - Medium - October 14, 2021

The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path traversal vulnerability. Exploitation of this results in a malicious actor having the ability to arbitrarily delete files on the local system.

Directory traversal

The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting

CVE-2021-33179 6.1 - Medium - October 14, 2021

The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload.

XSS

Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php

CVE-2021-37223 6.5 - Medium - October 05, 2021

Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI application. Due to lack of input sanitisation, the target page can be replaced with an SSRF payload to access internal resources or disclose local system files.

SSRF

Nagios XI before 5.8.5 incorrectly

CVE-2021-36364 9.8 - Critical - September 28, 2021

Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.

Nagios XI before 5.8.5 incorrectly

CVE-2021-36366 9.8 - Critical - September 28, 2021

Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards.

Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

CVE-2021-36363 9.8 - Critical - September 28, 2021

Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

Incorrect Default Permissions

Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

CVE-2021-36365 9.8 - Critical - September 28, 2021

Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

Incorrect Default Permissions

In Nagios XI before 5.8.6

CVE-2021-38156 5.4 - Medium - September 15, 2021

In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.

XSS

Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.

CVE-2021-37350 9.8 - Critical - August 13, 2021

Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.

SQL Injection

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation

CVE-2021-37349 7.8 - High - August 13, 2021

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database.

Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.

CVE-2021-37348 7.5 - High - August 13, 2021

Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.

Files or Directories Accessible to External Parties

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation

CVE-2021-37347 7.8 - High - August 13, 2021

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.

Directory traversal

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation

CVE-2021-37345 7.8 - High - August 13, 2021

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.

Improper Privilege Management

A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.

CVE-2021-37343 8.8 - High - August 13, 2021

A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.

Directory traversal

Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection).

CVE-2021-37346 9.8 - Critical - August 13, 2021

Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection).

Shell injection

Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.