Known vulnerabilities in Cacti

Software: Cacti
Software CPE: cpe:2.3:a:the_cacti_group:cacti:*:*:*:*:*:*:*:*
Total vulnerabilities: 120
Public exploits: 12
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cacti Cacti is affected by 120 known vulnerabilities: 1 critical, 16 high, 38 medium, 65 low Critical High Medium Low

Vulnerabilities (120)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139916 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-39902
CWE-78 Low
No
No
1.2.31 28.07.2026 SB20260619121
#VU134993 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-40083
CWE-89 Low
No
No
1.2.31 22.06.2026 SB20260619121
#VU134992 - Observable Response Discrepancy
CVE-2026-49442
CWE-204 Medium
No
No
1.2.31 22.06.2026 SB20260619121
#VU134991 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-40084
CWE-22 Low
No
No
1.2.31 22.06.2026 SB20260619121
#VU134990 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-40079
CWE-78 Medium
No
No
1.2.31 22.06.2026 SB20260619121
#VU134989 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2026-40080
CWE-601 Medium
No
No
1.2.31 22.06.2026 SB20260619121
#VU134988 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-39948
CWE-89 High
No
No
1.2.31 22.06.2026 SB20260619121
#VU134987 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-39955
CWE-89 High
No
No
1.2.31 22.06.2026 SB20260619121
#VU134986 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-39938
CWE-22 High
No
No
1.2.31 22.06.2026 SB20260619121
#VU134985 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-39893
CWE-89 High
No
No
1.2.31 22.06.2026 SB20260619121
#VU134962 - Session Fixation
CVE-2026-40082
CWE-384 Medium
No
No
1.2.31 19.06.2026 SB20260619121
#VU134961 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-39897
CWE-79 Medium
No
No
1.2.31 19.06.2026 SB20260619121
#VU134960 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-39900
CWE-79 Medium
No
No
1.2.31 19.06.2026 SB20260619121
#VU134959 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-39899
CWE-22 Low
No
No
1.2.31 19.06.2026 SB20260619121
#VU134958 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-39951
CWE-89 Low
No
No
1.2.31 19.06.2026 SB20260619121
#VU134957 - Improper Verification of Cryptographic Signature
CVE-2026-40941
CWE-347 Medium
No
No
1.2.31 19.06.2026 SB20260619121
#VU134956 - Use of Function with Inconsistent Implementations
CVE-2026-39894
CWE-474 Low
No
No
1.2.31 19.06.2026 SB20260619121
#VU134955 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-46531
CWE-89 Low
No
No
1.2.31 19.06.2026 SB20260619121
#VU118996 - Command injection
CVE-2025-66399
CWE-77 Medium
No
No
1.2.29 02.12.2025 SB2025120226
#VU103306 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-54146
CWE-89 Low
No
No
1.2.29 27.01.2025 SB2025012719


Showing elements 1 - 20 out of 120