The Cacti Group maintains a focused network monitoring and graphing platform that, despite a narrow product footprint, is widely deployed in infrastructure environments for real-time performance tracking and alerting. The vendor's vulnerability profile centers on its Cacti application and recurs through SQL injection and related input-handling weaknesses characteristic of web-based data-collection systems, with a notable tendency for disclosed flaws to acquire public exploit code. Defenders should prioritize patching internet-exposed Cacti instances and restrict administrative access; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by The Cacti Group over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0147HIGH Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) | Jan 9, 2006 | 7.5 | 36 | NO | YES |
CVE-2005-1526HIGH PHP remote file inclusion vulnerability in config_settings.php in Cacti before 0.8.6e allows remote attackers to execute arbitrary PHP code via the config[include_path] parameter. | Jun 22, 2005 | 7.5 | 36 | NO | YES |
CVE-2006-0146HIGH The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MA | Jan 9, 2006 | 7.5 | 34 | NO | YES |
CVE-2005-1524MEDIUM PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the config[library_ | Jun 22, 2005 | 5.0 | 29 | NO | YES |
CVE-2004-1737HIGH SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) passwo | Aug 16, 2004 | 7.5 | 29 | NO | YES |
CVE-2005-2149HIGH config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslash | Jul 6, 2005 | 10.0 | 25 | NO | NO |
CVE-2002-1478HIGH Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode. | Apr 22, 2003 | 10.0 | 25 | NO | NO |
CVE-2007-3112HIGH graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_st | Jun 7, 2007 | 7.8 | 20 | NO | NO |
CVE-2006-6799HIGH SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) thi | Dec 28, 2006 | 7.5 | 20 | NO | NO |
CVE-2005-2148HIGH Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a | Jul 6, 2005 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by The Cacti Group.
Media articles that mention a CVE ID that affects a product developed by The Cacti Group — matched by CVE ID, not by vendor name.