pnp4nagios CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

pnp4nagios vulnerability overview

Aggregates CVE and security vulnerability intelligence across all pnp4nagios-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk cross-site scripting and vendor risk csrf, with potential vendor impact session compromise across vendor surface software deployment and vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-38350 PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26. [email protected] 5.4 0.45% 2023-07-14 2026-06-17
CVE-2023-38349 PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26. [email protected] 8.8 0.25% 2023-07-14 2026-06-17
CVE-2017-16834 PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account. [email protected] 7.8 0.36% 2017-11-15 2026-06-16
CVE-2014-4908 Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) share/pnp/application/views/kohana_error_page.php or (2) share/pnp/application/views/template.php, leading to improper handling within an http-equiv="refresh" META element. [email protected] 4.3 1.91% 2014-07-11 2026-06-16
CVE-2014-4907 Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properly handled in an error message. [email protected] 4.3 2.21% 2014-07-11 2026-06-16
CVE-2012-3457 PNP4Nagios 0.6 through 0.6.16 uses world-readable permissions for process_perfdata.cfg, which allows local users to obtain the Gearman shared secret by reading the file. [email protected] 2.1 0.34% 2012-08-11 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence