Nagios
XI
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
Official registry publication history is available at xi, but registry activity is not a publisher support boundary.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2021-47698 | 3 Nov 2025 | < 5.8.7 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2024-13997 | 3 Nov 2025 | XI: < 2024R1.1.3 | Nagios addresses this vulnerability as "Nagios XI was vulnerable to a privilege escalation wherein an administrator using the Migrate Server feature could become root on the XI server." | Update reference ↗ |
| CVE-2024-13998 | 3 Nov 2025 | XI: < 2024R1.1.3 | Nagios addresses this vulnerability as "Nagios XI could, under certain circumstances, leak other users' API tokens or hashed passwords to other authenticated users." | Update reference ↗ |
| CVE-2024-13992 | 31 Oct 2025 | XI: < 2024R1.1 | Nagios addresses this vulnerability as "Nagios XI is vulnerable to a cross-site scripting (XSS) vulnerability when visiting the "missing page" page from another website" and "Fixed XSS in page-missing.php." | Update reference ↗ |
| CVE-2011-10037 | 30 Oct 2025 | < 2011R1.9 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2021-47697 | 30 Oct 2025 | < 5.8.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2018-25121 | 30 Oct 2025 | < 5.4.13 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2013-10074 | 30 Oct 2025 | < 2012R2.6 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2011-10040 | 30 Oct 2025 | < 2011R1.9 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2016-15051 | 30 Oct 2025 | < 5.2.4 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2011-10038 | 30 Oct 2025 | < 2011R1.9 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2021-47695 | 30 Oct 2025 | < 5.8.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2016-15053 | 30 Oct 2025 | < 5.2.4 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2016-15052 | 30 Oct 2025 | < 5.2.4 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-36866 | 30 Oct 2025 | < 5.7.3 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2023-7316 | 30 Oct 2025 | < 2024R1 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2023-7315 | 30 Oct 2025 | < 5.11.3 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2024-14001 | 30 Oct 2025 | XI: < 2024R1.1.3 | Nagios addresses this vulnerability as "Nagios XI was vulnerable to a cross-site scripting (XSS) attack in the Executive Summary Report" and as part of "Fixed both XSS in Executive Summary report and ajaxhelper endpoint that was too open." | Update reference ↗ |
| CVE-2020-36864 | 30 Oct 2025 | < 5.7.2 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2023-7318 | 30 Oct 2025 | < 2024R1.0.2 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2024-14000 | 30 Oct 2025 | XI: < 2024R1.1.3 | Nagios addresses this vulnerability as "Nagios XI was vulnerable to a cross-site scripting (XSS) attack in the Capacity Planning Report" and "Fixed XSS in Capacity Planning component." | Update reference ↗ |
| CVE-2023-7313 | 30 Oct 2025 | < 5.11.3 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-36865 | 30 Oct 2025 | < 5.7.2 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2021-47696 | 30 Oct 2025 | < 5.8.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2023-7314 | 30 Oct 2025 | < 5.11.3 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2011-10036 | 30 Oct 2025 | < 2011R1.9 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2011-10039 | 30 Oct 2025 | < 2011R1.9 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2021-47699 | 30 Oct 2025 | < 5.8.7 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2023-53688 | 30 Oct 2025 | < 5.11.3 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2023-7317 | 30 Oct 2025 | < 2024R1 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-36863 | 30 Oct 2025 | < 5.7.2 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-36862 | 30 Oct 2025 | < 5.6.11 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2022-50587 | 30 Oct 2025 | < 5.8.9 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2022-50586 | 30 Oct 2025 | < 5.8.9 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2022-50588 | 30 Oct 2025 | < 5.8.9 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-36869 | 30 Oct 2025 | < 5.7.5 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2016-15050 | 30 Oct 2025 | < 5.2.4 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2024-13996 | 30 Oct 2025 | XI: < 2024R1.1.3 | Nagios addresses this vulnerability as "When changing a user's password, Nagios XI did not invalidate all other existing sessions for that user" and "Fixed an issue where a password change wouldn’t invalidate other sessions." | Update reference ↗ |
| CVE-2024-13993 | 30 Oct 2025 | XI: < 2024R1.1.2 | Nagios addresses this vulnerability as "Nagios XI 2024R1.1.1 and earlier may be vulnerable to a reflected XSS in its login page when using older browsers" (within the "Security Disclosures" site) and it's unclear where or if it's addressed within the changelog. | Update reference ↗ |
| CVE-2013-10071 | 30 Oct 2025 | < 2012R1.6 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2024-14008 | 30 Oct 2025 | XI: < 2024R1.3.2 | Nagios addresses this vulnerability as "Nagios XI was vulnerable to remote command execution through the WinRM configuration wizard" and as a part of "Fixed RCE in WinRM Wizard." | Update reference ↗ |
| CVE-2025-34286 | 30 Oct 2025 | XI: < 2026R1 | Nagios addresses this vulnerability as "Nagios XI was vulnerable to Remote Code Execution via the Run Check command in the CCM" and "Fixed an RCE vulnerability with the Run Check Command in the CCM." | Update reference ↗ |
| CVE-2024-14003 | 30 Oct 2025 | XI: < 2024R1.2 | Nagios addresses this vulnerability as "Nagios XI was vulnerable to remote code execution through NRDP" and "Improved validation in several NRDP server plugins." | Update reference ↗ |
| CVE-2025-34134 | 30 Oct 2025 | XI: < 2024R1.4.2 | Nagios addresses this vulnerability as "Nagios XI was vulnerable to remote code execution via the Business Process Intelligence (BPI) component" and "Fixed an issue with BPI configuration and log files." | Update reference ↗ |
| CVE-2011-10035 | 30 Oct 2025 | < 2011R1.9 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2024-14009 | 30 Oct 2025 | XI: < 2024R1.0.1 | Nagios addresses this vulnerability as "The System Profile component is vulnerable to a privilege escalation attack" and "Fix an privilege escalation vulnerability in the System Profile component." | Update reference ↗ |
| CVE-2024-14004 | 30 Oct 2025 | XI: < 2024R1.2 | Nagios addresses this vulnerability as "Nagios XI was vulnerable to privilege escalation via nagvis.conf" and "Fixed privilege escalation via nagvis.conf ." | Update reference ↗ |
| CVE-2018-25123 | 30 Oct 2025 | < 5.5.7 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-36868 | 30 Oct 2025 | < 5.7.3 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-34287 | 30 Oct 2025 | XI: < 2024R2 | Nagios addresses this vulnerability as "Changed ownership on process_perfdata.pl to prevent permission escalation" | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.