Netbox is a widely deployed open-source infrastructure resource-planning and asset-management platform that serves as a source-of-truth database for network and datacenter environments. The vulnerability exposure centers on its single product and recurs through application-layer weakness classes including cross-site scripting, code injection, and input-handling gaps characteristic of web-facing administrative interfaces. The platform's role as a centralized management system means that flaws affecting it can carry broad downstream risk across the infrastructure inventory it controls. Defenders should monitor this vendor's release cycle and treat Netbox instances as requiring timely patching, particularly when internet-accessible; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netbox over time
Signals from CVEs in this vendor scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33796CRITICAL A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, granting them access to sensitive data stored in the database. NO | May 24, 2023 | 9.1 | 26 | NO | NO |
CVE-2025-57543MEDIUM Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitrary HTML, which will be rendered in the web UI when viewed by | Mar 16, 2026 | 6.1 | 21 | NO | NO |
CVE-2025-69848MEDIUM NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through | Feb 3, 2026 | 5.4 | 19 | NO | NO |
CVE-2024-56917HIGH Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode. | Jun 24, 2025 | 7.1 | 19 | NO | NO |
CVE-2024-40733MEDIUM A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dci | Jul 9, 2024 | 6.1 | 19 | NO | NO |
CVE-2019-25011MEDIUM NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as demonstrated by /dcim/sites/add/ comments. | Dec 31, 2020 | 5.4 | 19 | NO | NO |
CVE-2024-56915MEDIUM Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget. | Jun 26, 2025 | 6.5 | 18 | NO | NO |
CVE-2024-56916MEDIUM In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) due to the `current value` field rendering user supplied html | Jun 24, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-56918MEDIUM In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authenticated attacker to exfiltrate user input from the login for | Jun 24, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-47226MEDIUM A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. A | Sep 22, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (46 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netbox.
Media articles that mention a CVE ID that affects a product developed by Netbox — matched by CVE ID, not by vendor name.