Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cacti

First CVE: Nov 20, 2007Active for: 19 yearsTotal CVEs: 153
68.7
VTI Score
TOP TARGET

Cacti is a modestly sized but prominently deployed open-source monitoring and graphing platform, and despite the narrow product scope, its widespread use in network operations centers creates substantial reach. Vulnerabilities affecting the vendor concentrate in input-handling and injection attack surface, with recurring weakness classes including cross-site scripting, SQL injection, OS command injection, code injection, and improper input validation that reflect the web application's exposure to untrusted parameters. Public exploit code frequently becomes available for Cacti vulnerabilities, making disclosed flaws an active remediation concern. Defenders should treat this vendor's advisories with urgency given the internet-facing nature of monitoring dashboards and the injection-class patterns that recur across releases; live severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
153
Total CVEs
More Total CVEs than 100% of tracked vendors
3.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.7%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Cacti over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 20, 2007
18 years ago
Most Recent CVE
Jun 25, 2026
29 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (153 CVEs).

153 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-46169CRITICAL
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vu
Dec 5, 20229.899YESYES
CVE-2024-25641HIGH
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" fe
May 14, 20247.285NOYES
CVE-2023-39361CRITICAL
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can
Sep 5, 20239.884NOYES
CVE-2023-49085HIGH
Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script
Dec 22, 20238.880NOYES
CVE-2020-14295HIGH
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts sta
Jun 17, 20207.280NOYES
CVE-2020-8813HIGH
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.
Feb 22, 20208.880NOYES
CVE-2023-49084HIGH
Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient proc
Dec 21, 20238.872NOYES
CVE-2023-39362HIGH
Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious stri
Sep 5, 20237.272NOYES
CVE-2025-24367HIGH
Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP sc
Jan 27, 20258.869NOYES
CVE-2024-54146HIGH
Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the template function of host_templates.php using the graph_template
Jan 27, 20258.845NONO
View all 153 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products153 CVEs
52%
39%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (1.3%)
Network112 (73.2%)
Unknown39 (25.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low113 (73.9%)
High1 (0.7%)
Unknown39 (25.5%)
User Interaction
None62 (40.5%)
Unknown39 (25.5%)
Required52 (34.0%)
Privileges Required
Low58 (37.9%)
High21 (13.7%)
None35 (22.9%)
Unknown39 (25.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (153 CVEs).

CISA KEV
1 CVE
0.7% of CVEs· 99th percentile
Metasploit
7 CVEs
4.6% of CVEs· 98th percentile
Nuclei
5 CVEs
3.3% of CVEs· 95th percentile
ExploitDB
13 CVEs
8.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cacti.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cacti — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cacti's Products

View all 7 CNAs →

Top CWEs