CVE-2018-10738: Nagios XI

High severity, CVSS 7.2. EPSS: 42.1% chance of exploitation in the next 30 days.

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.

Affected products

  • Nagios Nagios XI: from 5.2.0, up to and including 5.2.9; from 5.4.0, before 5.4.13 (fixed in 5.4.13)

Published 2018-05-16. Last modified 2026-06-17.