CVE-2017-16785: Cacti

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.

Affected products

  • Cacti Cacti: version 1.1.27 only

Published 2017-11-10. Last modified 2026-06-17.