CVE-2020-28903: Nagios Fusion

Medium severity, CVSS 6.1. EPSS: 13.2% chance of exploitation in the next 30 days.

Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS.

Affected products

  • Nagios Fusion: up to and including 4.1.8

Published 2021-05-24. Last modified 2026-06-17.