CVE-2012-10029: Nagios Enterprises Nagios XI Graph Explorer

High severity, CVSS 8.6. EPSS: 3.6% chance of exploitation in the next 30 days.

Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution.

Affected products

Published 2025-08-05. Last modified 2026-06-16.