CVE-2024-27082: Cacti

Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.

Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server and served to users who access a particular page. Version 1.2.27 contains a patch for the issue.

Affected products

  • Cacti Cacti: before 1.2.27 (fixed in 1.2.27)

Published 2024-05-14. Last modified 2026-06-17.