Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pnp4nagios

First CVE: Aug 12, 2012Active for: 14 yearsTotal CVEs: 6

Pnp4nagios is a web-based graphing and reporting extension for Nagios monitoring systems that, despite a narrow product focus, occupies a notable role in infrastructure visibility stacks where monitoring data is exposed to multiple users and networks. Its vulnerability profile concentrates on web-application input-handling and access-control issues—particularly cross-site scripting, cross-site request forgery, and improper permission assignment—that are characteristic of administrative interfaces where trust boundaries and data validation matter to the integrity of monitoring visibility. Defenders managing Pnp4nagios deployments should prioritize network segmentation of the graphing interface and treat this vendor's advisories as relevant to their monitoring tier; live severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
5.5
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pnp4nagios over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2012
13 years ago
Most Recent CVE
Jul 15, 2023
1,109 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-38349HIGH
PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26.
Jul 15, 20238.824NONO
CVE-2017-16834HIGH
PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privilege
Nov 16, 20177.824NONO
CVE-2014-4907MEDIUM
Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or
Jul 11, 20144.318NONO
CVE-2023-38350MEDIUM
PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26.
Jul 15, 20235.417NONO
CVE-2014-4908MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) sha
Jul 11, 20144.317NONO
CVE-2012-3457LOW
PNP4Nagios 0.6 through 0.6.16 uses world-readable permissions for process_perfdata.cfg, which allows local users to obtain the Gearman shared secret by reading the file.
Aug 12, 20122.113NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
17%
50%
33%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (16.7%)
Network2 (33.3%)
Unknown3 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (50.0%)
High0 (0.0%)
Unknown3 (50.0%)
User Interaction
None1 (16.7%)
Unknown3 (50.0%)
Required2 (33.3%)
Privileges Required
Low2 (33.3%)
High0 (0.0%)
None1 (16.7%)
Unknown3 (50.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pnp4nagios.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pnp4nagios — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pnp4nagios's Products

View all 2 CNAs →

Top CWEs