the cacti group inc.
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting the cacti group inc..
- CVE-2025-66399SNMP Command Injection leads to RCE in Cacti8.8
- CVE-2025-26520Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists because of an incomplete fix for CVE-2024-54146.7.6
- CVE-2025-24368Cacti has a SQL Injection vulnerability when using tree rules through Automation API7.5
- CVE-2025-24367Cacti allows Arbitrary File Creation leading to RCE8.8
- CVE-2025-22604Cacti has Authenticated RCE via multi-line SNMP responses9.1
- CVE-2024-54145Cacti has a SQL Injection vulnerability when request automation devices6.3
- CVE-2024-54146Cacti has a SQL Injection vulnerability when view host template7.6
- CVE-2024-45598Cacti has a Local File Inclusion (LFI) Vulnerability via Poller Standard Error Log Path6.0
- CVE-2024-43363Remote code execution via Log Poisoning in Cacti7.2
- CVE-2024-43365Stored Cross-site Scripting (XSS) when creating external links in Cacti5.7
- CVE-2024-43364Stored Cross-site Scripting (XSS) when creating external links in Cacti5.7
- CVE-2024-43362Stored Cross-site Scripting (XSS) when creating external links in Cacti7.3
- CVE-2024-31460Cacti SQL Injection vulnerability in lib/api_automation.php caused by reading dirty data stored in database6.5
- CVE-2024-31459Cacti RCE vulnerability by file include in lib/plugin.php8.0
- CVE-2024-31458Cacti SQL Injection vulnerability in lib/html_form_templates.php by reading dirty data stored in database4.6