Cacti is a modestly sized but prominently deployed open-source monitoring and graphing platform, and despite the narrow product scope, its widespread use in network operations centers creates substantial reach. Vulnerabilities affecting the vendor concentrate in input-handling and injection attack surface, with recurring weakness classes including cross-site scripting, SQL injection, OS command injection, code injection, and improper input validation that reflect the web application's exposure to untrusted parameters. Public exploit code frequently becomes available for Cacti vulnerabilities, making disclosed flaws an active remediation concern. Defenders should treat this vendor's advisories with urgency given the internet-facing nature of monitoring dashboards and the injection-class patterns that recur across releases; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cacti over time
Signals from CVEs in this vendor scope (153 CVEs).
153 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-46169CRITICAL Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vu | Dec 5, 2022 | 9.8 | 99 | YES | YES |
CVE-2024-25641HIGH Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" fe | May 14, 2024 | 7.2 | 85 | NO | YES |
CVE-2023-39361CRITICAL Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can | Sep 5, 2023 | 9.8 | 84 | NO | YES |
CVE-2023-49085HIGH Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script | Dec 22, 2023 | 8.8 | 80 | NO | YES |
CVE-2020-14295HIGH A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts sta | Jun 17, 2020 | 7.2 | 80 | NO | YES |
CVE-2020-8813HIGH graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege. | Feb 22, 2020 | 8.8 | 80 | NO | YES |
CVE-2023-49084HIGH Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient proc | Dec 21, 2023 | 8.8 | 72 | NO | YES |
CVE-2023-39362HIGH Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious stri | Sep 5, 2023 | 7.2 | 72 | NO | YES |
CVE-2025-24367HIGH Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP sc | Jan 27, 2025 | 8.8 | 69 | NO | YES |
CVE-2024-54146HIGH Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the template function of host_templates.php using the graph_template | Jan 27, 2025 | 8.8 | 45 | NO | NO |
Signals from CVEs in this vendor scope (153 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cacti.
Media articles that mention a CVE ID that affects a product developed by Cacti — matched by CVE ID, not by vendor name.