CVE-2017-12978: Cacti

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

Affected products

  • Cacti Cacti: up to and including 1.1.17

Published 2017-08-21. Last modified 2026-06-17.