Vulnerabilities > Nagios > Nagios XI > Low

DATE CVE VULNERABILITY TITLE RISK
2019-06-19 CVE-2018-17146 Cross-site Scripting vulnerability in Nagios XI
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page.
network
nagios CWE-79
3.5
2018-11-14 CVE-2018-15713 Cross-site Scripting vulnerability in Nagios XI 5.5.6
Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php.
network
nagios CWE-79
3.5
2018-04-30 CVE-2018-10554 Cross-Site Request Forgery (CSRF) vulnerability in Nagios XI 5.4.13
An issue was discovered in Nagios XI 5.4.13.
network
nagios CWE-352
3.5