CVE-2018-10736: Nagios XI

High severity, CVSS 7.2. EPSS: 42.1% chance of exploitation in the next 30 days.

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.

Affected products

  • Nagios Nagios XI: from 5.2.0, up to and including 5.2.9; from 5.4.0, before 5.4.13 (fixed in 5.4.13)

Published 2018-05-16. Last modified 2026-06-17.