The Cacti Group

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 16
    Known Exploited: 0
    3
    Critical Level Threats
    9
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-25641

    Cacti RCE vulnerability when importing packages

    Last Modified: Nov 04, 2025
    Published: May 13, 2024

    CVE-2007-3113

    Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_height or (2) graph_width parameter, different vectors than CVE-2007-3112.

    Last Modified: Apr 23, 2026
    Published: Jun 07, 2007

    CVE-2007-3112

    graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_start or (2) graph_end parameter, different vectors than CVE-2007-3113.

    Last Modified: Apr 23, 2026
    Published: Jun 07, 2007

    CVE-2006-6799

    SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php. NOTE: this issue can be leveraged to execute arbitrary commands since the SQL query results are later used in the polling_items array and popen function.

    Last Modified: Apr 23, 2026
    Published: Dec 28, 2006

    CVE-2006-0146

    The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.

    Last Modified: Apr 16, 2026
    Published: Jan 09, 2006
    Items Per Page
    The_Cacti_Group Vulnerabilities & Security CVEs | CVE-DB