Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Netbox

First CVE: Dec 31, 2020Active for: 6 yearsTotal CVEs: 46
15.9
VTI Score
Low

Netbox is a widely deployed open-source infrastructure resource-planning and asset-management platform that serves as a source-of-truth database for network and datacenter environments. The vulnerability exposure centers on its single product and recurs through application-layer weakness classes including cross-site scripting, code injection, and input-handling gaps characteristic of web-facing administrative interfaces. The platform's role as a centralized management system means that flaws affecting it can carry broad downstream risk across the infrastructure inventory it controls. Defenders should monitor this vendor's release cycle and treat Netbox instances as requiring timely patching, particularly when internet-accessible; current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
46
Total CVEs
More Total CVEs than 98% of tracked vendors
9.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 27% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Netbox over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2020
5 years ago
Most Recent CVE
Mar 16, 2026
130 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-33796CRITICAL
A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, granting them access to sensitive data stored in the database. NO
May 24, 20239.126NONO
CVE-2025-57543MEDIUM
Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitrary HTML, which will be rendered in the web UI when viewed by
Mar 16, 20266.121NONO
CVE-2025-69848MEDIUM
NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through
Feb 3, 20265.419NONO
CVE-2024-56917HIGH
Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.
Jun 24, 20257.119NONO
CVE-2024-40733MEDIUM
A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dci
Jul 9, 20246.119NONO
CVE-2019-25011MEDIUM
NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as demonstrated by /dcim/sites/add/ comments.
Dec 31, 20205.419NONO
CVE-2024-56915MEDIUM
Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget.
Jun 26, 20256.518NONO
CVE-2024-56916MEDIUM
In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) due to the `current value` field rendering user supplied html
Jun 24, 20256.118NONO
CVE-2024-56918MEDIUM
In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authenticated attacker to exfiltrate user input from the login for
Jun 24, 20256.118NONO
CVE-2024-47226MEDIUM
A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. A
Sep 22, 20245.418NONO
View all 46 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products46 CVEs
96%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network46 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low46 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (2.2%)
Unknown0 (0.0%)
Required45 (97.8%)
Privileges Required
Low21 (45.7%)
High0 (0.0%)
None25 (54.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (46 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Netbox.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Netbox — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Netbox's Products

View all 2 CNAs →

Top CWEs