CVE-2018-10553: Nagios XI

Medium severity, CVSS 6.5. EPSS: 38.4% chance of exploitation in the next 30 days.

An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginning with index.php?xiwindow=./ and config/?xiwindow=../ substrings.

Affected products

  • Nagios Nagios XI: version 5.4.13 only

Published 2018-04-30. Last modified 2026-06-17.