CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

nagios

fusion

19 known vulnerabilities · sorted by CVSS score

CVE-2020-28902
CRITICAL9.8

Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.

nagios / fusion
Network
Published May 24, 2021
CVE-2020-28908
CRITICAL9.8

Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.

nagios / fusion
Network
Published May 24, 2021
CVE-2020-28901
CRITICAL9.8

Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php.

nagios / fusion
Network
Published May 24, 2021
CVE-2020-28907
CRITICAL9.8

Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh.

nagios / fusion
Network
Published May 24, 2021
CVE-2020-28900
CRITICAL9.8

Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.

nagios / fusion+1
Network
Published May 24, 2021
CVE-2020-28904
CRITICAL9.8

Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious component containing PHP code.

nagios / fusion
Network
Published May 24, 2021
CVE-2020-28906
HIGH8.8

Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included (aka sourced) by scripts executed by root.

nagios / fusion+1
Network
Published May 24, 2021
CVE-2020-28909
HIGH8.8

Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification of scripts. Low-privileges users are able to modify files that can be executed by sudo.

nagios / fusion
Network
Published May 24, 2021
CVE-2020-28905
HIGH8.8

Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via table pagination.

nagios / fusion
Network
Published May 24, 2021
CVE-2025-60425
HIGH8.6

Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.

nagios / fusion+1
Network
Published Oct 27, 2025
CVE-2025-60424
HIGH7.6

A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.

nagios / fusion+1
Adjacent
Published Oct 27, 2025
CVE-2020-28911
MEDIUM6.5

Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php.

nagios / fusion
Network
Published May 24, 2021
CVE-2018-12501
MEDIUM6.1

Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335.

nagios / fusion
Network
Published Jun 16, 2018
CVE-2017-20209
MEDIUM6.1

Nagios Fusion versions prior to 4.0.1 are vulnerable to cross-site scripting (XSS) via the Users and Servers pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

nagios / fusion
Network
Published Oct 30, 2025
CVE-2018-25119
MEDIUM6.1

Nagios Fusion versions prior to 4.1.5 are vulnerable to cross-site scripting (XSS) via the "fusionwindow" parameter. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

nagios / fusion
Network
Published Oct 30, 2025
CVE-2020-28903
MEDIUM6.1

Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS.

nagios / fusion
Network
Published May 24, 2021
CVE-2023-53690
MEDIUM4.8

Nagios Fusion versions prior to 4.2.0 contain a stored cross-site scripting (XSS) vulnerability in the LDAP/AD authentication-server configuration. Unsanitized user input can be stored and later rendered in the administrative UI, causing JavaScript to execute in the browser of any user who views the affected page. An attacker who can add authentication servers via LDAP/AD integration could persist a malicious payload that executes in the context of other users' browsers.

nagios / fusion
Network
Published Oct 30, 2025
CVE-2023-7312
MEDIUM4.8

Nagios Fusion versions prior to 4.2.0 contain a stored cross-site scripting (XSS) vulnerability when adding or configuring Email Settings. Unsanitized user input can be stored and later rendered in the administrative UI, causing JavaScript to execute in the browser of any user who views the affected page. An attacker who can add or modify SMTP/email settings or manipulate the sendmail configuration fields could persist a malicious payload that executes in the context of other users' browsers.

nagios / fusion
Network
Published Oct 30, 2025
CVE-2023-53689
MEDIUM4.8

Nagios Fusion versions prior to 4.2.0 contain a reflected cross-site scripting (XSS) vulnerability in the license key configuration flow that can result in execution of attacker-controlled script in the browser of a user who follows a crafted URL. While the application server itself is not directly corrupted by the reflected XSS, the resulting browser compromise can lead to credential/session theft and unauthorized administrative actions.

nagios / fusion
Network
Published Oct 30, 2025