Fusion Nagios Fusion

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Nagios Fusion.

By the Year

In 2026 there have been 0 vulnerabilities in Nagios Fusion. Last year, in 2025 Fusion had 8 security vulnerabilities published. Right now, Fusion is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 8 7.60
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 11 8.89
2020 0 0.00
2019 0 0.00
2018 1 6.10

It may take a day or so for new Fusion vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Nagios Fusion Security Vulnerabilities

Nagios Fusion XSS Users/Servers (<4.0.1)
CVE-2017-20209 - October 30, 2025

Nagios Fusion versions prior to 4.0.1 are vulnerable to cross-site scripting (XSS) via the Users and Servers pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

XSS

Nagios Fusion <4.1.5 XSS via fusionwindow parameter
CVE-2018-25119 - October 30, 2025

Nagios Fusion versions prior to 4.1.5 are vulnerable to cross-site scripting (XSS) via the "fusionwindow" parameter. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

XSS

Nagios Fusion <4.2.0 Reflected XSS in License Key Config
CVE-2023-53689 - October 30, 2025

Nagios Fusion versions prior to 4.2.0 contain a reflected cross-site scripting (XSS) vulnerability in the license key configuration flow that can result in execution of attacker-controlled script in the browser of a user who follows a crafted URL. While the application server itself is not directly corrupted by the reflected XSS, the resulting browser compromise can lead to credential/session theft and unauthorized administrative actions.

XSS

Nagios Fusion <4.2 XSS in LDAP/AD Auth-Server Config
CVE-2023-53690 - October 30, 2025

Nagios Fusion versions prior to 4.2.0 contain a stored cross-site scripting (XSS) vulnerability in the LDAP/AD authentication-server configuration. Unsanitized user input can be stored and later rendered in the administrative UI, causing JavaScript to execute in the browser of any user who views the affected page. An attacker who can add authentication servers via LDAP/AD integration could persist a malicious payload that executes in the context of other users' browsers.

XSS

Nagios Fusion <4.2.0 Stored XSS via Email Settings
CVE-2023-7312 - October 30, 2025

Nagios Fusion versions prior to 4.2.0 contain a stored cross-site scripting (XSS) vulnerability when adding or configuring Email Settings. Unsanitized user input can be stored and later rendered in the administrative UI, causing JavaScript to execute in the browser of any user who views the affected page. An attacker who can add or modify SMTP/email settings or manipulate the sendmail configuration fields could persist a malicious payload that executes in the context of other users' browsers.

XSS

Nagios Fusion <=2024R2.1 2FA Brute-Force Bypass
CVE-2025-34249 - October 30, 2025

Rate Limiting Flaw in Nagios Fusion v2024 OTP Brute-Force Auth Bypass
CVE-2025-60424 7.6 - High - October 27, 2025

A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.

Improper Restriction of Excessive Authentication Attempts

Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier
CVE-2020-28900 9.8 - Critical - May 24, 2021

Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.

Insufficient Verification of Data Authenticity

Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root
CVE-2020-28906 8.8 - High - May 24, 2021

Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included (aka sourced) by scripts executed by root.

Incorrect Default Permissions

Command Injection in Nagios Fusion 4.1.8 and earlier
CVE-2020-28902 9.8 - Critical - May 24, 2021

Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.

Command Injection

Improper input validation in Nagios Fusion 4.1.8 and earlier
CVE-2020-28903 6.1 - Medium - May 24, 2021

Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS.

XSS

Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier
CVE-2020-28904 9.8 - Critical - May 24, 2021

Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious component containing PHP code.

Improper Privilege Management

Improper Input Validation in Nagios Fusion 4.1.8 and earlier
CVE-2020-28905 8.8 - High - May 24, 2021

Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via table pagination.

Code Injection

Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier
CVE-2020-28907 9.8 - Critical - May 24, 2021

Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh.

Improper Certificate Validation

Command Injection in Nagios Fusion 4.1.8 and earlier
CVE-2020-28901 9.8 - Critical - May 24, 2021

Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php.

Command Injection

Command Injection in Nagios Fusion 4.1.8 and earlier
CVE-2020-28908 9.8 - Critical - May 24, 2021

Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.

Command Injection

Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification of scripts
CVE-2020-28909 8.8 - High - May 24, 2021

Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification of scripts. Low-privileges users are able to modify files that can be executed by sudo.

Incorrect Permission Assignment for Critical Resource

Incorrect Access Control in Nagios Fusion 4.1.8 and earlier
CVE-2020-28911 6.5 - Medium - May 24, 2021

Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php.

Insecure Storage of Sensitive Information

Nagios Fusion before 4.1.4 has XSS
CVE-2018-12501 6.1 - Medium - June 16, 2018

Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Nagios Fusion or by Nagios? Click the Watch button to subscribe.

Nagios
Vendor

Nagios Fusion
Product

subscribe