CVE-2020-25706: Cacti

Medium severity, CVSS 6.1. EPSS: 2.8% chance of exploitation in the next 30 days.

A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field

Affected products

  • Cacti Cacti: version 1.2.13 only
  • Debian Debian Linux: version 10.0 only

Published 2020-11-12. Last modified 2026-06-17.