Network Analyzer Nagios Network Analyzer

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Nagios Network Analyzer.

By the Year

In 2026 there have been 0 vulnerabilities in Nagios Network Analyzer. Last year, in 2025 Network Analyzer had 6 security vulnerabilities published. Right now, Network Analyzer is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 6 0.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 2 7.95

It may take a day or so for new Network Analyzer vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Nagios Network Analyzer Security Vulnerabilities

Nagios Network Analyzer XSS via Percentile Calculator Menu CVE-2023-7319
CVE-2023-7319 - October 30, 2025

Nagios Network Analyzer versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Percentile Calculator menu. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

XSS

Nagios Network Analyzer Stored XSS in Source Groups Page
CVE-2025-34278 - October 30, 2025

Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can supply a malicious payload which is stored by the application and later rendered in the context of other users. When a victim views the affected page the injected script executes in the victim's browser context.

XSS

Nagios Network Analyzer <2024R2.0.1 RCE via Unsanitized LDAP Cert Remove
CVE-2025-34280 - October 30, 2025

Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administrator can trigger command execution on the underlying host in the context of the web application service, resulting in remote code execution with the service's privileges.

Shell injection

Nagios Network Analyzer 2024R1.0.3 Access Control: Deleted Users Remain Privileged
CVE-2025-28059 - April 18, 2025

An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend fails to terminate active sessions and revoke associated API tokens, enabling unauthorized access to restricted functions.

Broken Access Control in Nagios NA 2024R1.0.3 Allows Read-Only to Delete Services
CVE-2025-28131 - April 01, 2025

A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due to improper authorization enforcement, enabling unauthorized modifications that compromise system integrity and availability.

Session Token Reuse in Nagios Network Analyzer 2024R1.0.3
CVE-2025-28132 - April 01, 2025

A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized access and account takeover. This occurs due to insufficient session expiration, where session tokens remain valid beyond logout, allowing an attacker to impersonate users and perform actions on their behalf.

Self Authenticated XSS in Nagios Network Analyzer before 2.4.2
CVE-2021-28924 6.1 - Medium - April 08, 2021

Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page.

XSS

SQL injection vulnerability in Nagios Network Analyzer before 2.4.3
CVE-2021-28925 9.8 - Critical - April 08, 2021

SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/.

SQL Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Nagios Network Analyzer or by Nagios? Click the Watch button to subscribe.

Nagios
Vendor

subscribe