Aggregates CVE and security vulnerability intelligence across all pnp4nagios-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Common weakness patterns include vendor risk cross-site scripting and vendor risk csrf, with potential vendor impact session compromise across vendor surface software deployment and vendor surface production workloads use cases.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-38350 | PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26. | [email protected] | 5.4 | 0.45% | 2023-07-14 | 2026-06-17 |
| CVE-2023-38349 | PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26. | [email protected] | 8.8 | 0.25% | 2023-07-14 | 2026-06-17 |
| CVE-2017-16834 | PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account. | [email protected] | 7.8 | 0.36% | 2017-11-15 | 2026-06-16 |
| CVE-2014-4908 | Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) share/pnp/application/views/kohana_error_page.php or (2) share/pnp/application/views/template.php, leading to improper handling within an http-equiv="refresh" META element. | [email protected] | 4.3 | 1.91% | 2014-07-11 | 2026-06-16 |
| CVE-2014-4907 | Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properly handled in an error message. | [email protected] | 4.3 | 2.21% | 2014-07-11 | 2026-06-16 |
| CVE-2012-3457 | PNP4Nagios 0.6 through 0.6.16 uses world-readable permissions for process_perfdata.cfg, which allows local users to obtain the Gearman shared secret by reading the file. | [email protected] | 2.1 | 0.34% | 2012-08-11 | 2026-06-16 |