CVE-2026-39900: medium-severity vulnerability in cacti
Cacti: Reflected XSS via tab parameter in auth_profile.php JavaScript context
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.3%
exploitation probability
0.3%top 83% of all CVEs
observed exploitation
nono source reports it
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflected XSS via tab parameter in the auth_profile.php JavaScript context. This issue has been fixed in version 1.2.31.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
Cacti · cactiRelated CVEs — cacti
In the same product, most dangerous first.
CVE-2022-46169CRITICALUnauthenticated Command InjectionEPSS 99.8%KEVCVE-2024-29895CRITICALCacti command injection in cmd_realtime.phpEPSS 98.5%CVE-2023-39361CRITICALUnauthenticated SQL Injection in graph_view.php in CactiEPSS 88.8%CVE-2024-25641CRITICALCacti RCE vulnerability when importing packagesEPSS 86.3%CVE-2023-39362HIGHAuthenticated command injection in SNMP options of a DeviceEPSS 85.4%CVE-2023-49085HIGHCacti SQL Injection vulnerabilityEPSS 74.5%