Pnp4nagios is a web-based graphing and reporting extension for Nagios monitoring systems that, despite a narrow product focus, occupies a notable role in infrastructure visibility stacks where monitoring data is exposed to multiple users and networks. Its vulnerability profile concentrates on web-application input-handling and access-control issues—particularly cross-site scripting, cross-site request forgery, and improper permission assignment—that are characteristic of administrative interfaces where trust boundaries and data validation matter to the integrity of monitoring visibility. Defenders managing Pnp4nagios deployments should prioritize network segmentation of the graphing interface and treat this vendor's advisories as relevant to their monitoring tier; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pnp4nagios over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38349HIGH PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26. | Jul 15, 2023 | 8.8 | 24 | NO | NO |
CVE-2017-16834HIGH PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privilege | Nov 16, 2017 | 7.8 | 24 | NO | NO |
CVE-2014-4907MEDIUM Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or | Jul 11, 2014 | 4.3 | 18 | NO | NO |
CVE-2023-38350MEDIUM PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26. | Jul 15, 2023 | 5.4 | 17 | NO | NO |
CVE-2014-4908MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) sha | Jul 11, 2014 | 4.3 | 17 | NO | NO |
PNP4Nagios 0.6 through 0.6.16 uses world-readable permissions for process_perfdata.cfg, which allows local users to obtain the Gearman shared secret by reading the file. | Aug 12, 2012 | 2.1 | 13 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pnp4nagios.
Media articles that mention a CVE ID that affects a product developed by Pnp4nagios — matched by CVE ID, not by vendor name.