CVE-2011-5223: Cacti

Medium severity, CVSS 4.3. EPSS: 2.1% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0.8.7i allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

Affected products

  • Cacti Cacti: up to and including 0.8.7h; version 0.5 only; version 0.6 only; version 0.6.1 only; version 0.6.2 only; version 0.6.3 only; …

Published 2012-10-25. Last modified 2026-06-16.