CVE-2025-24367
HIGHDescription
Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.
Is your site exposed to CVE-2025-24367?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cacti | cacti |
References
Advisories & Patches
Exploits
Other References
Frequently Asked Questions
What is CVE-2025-24367? +
How severe is CVE-2025-24367? +
What products are affected by CVE-2025-24367? +
How do I check if I'm vulnerable to CVE-2025-24367? +
Related Vulnerabilities
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain …
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored …
Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is …
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and …
Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was …
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due …