Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY77 SECURITY RECORDS

Nagios

XI

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

Official registry publication history is available at xi, but registry activity is not a publisher support boundary.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2025-34135 30 Oct 2025 XI: < 2024R1.4.2 Nagios addresses this vulnerability as "Nagios XI had some Systemd unit files with permission sets that were too permissive" and "Fixed a permissions insecurity for nagios.service (removed execute permissions)." Update reference ↗
CVE-2021-47700 30 Oct 2025 < 5.8.7 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-14006 30 Oct 2025 XI: < 2024R1.2.2 Nagios addresses this vulnerability as "Nagios XI was vulnerable to a host header injection attack" and as a part of "Fixed a vulnerability to host header injection attacks." Update reference ↗
CVE-2018-25122 30 Oct 2025 < 5.4.13 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-14005 30 Oct 2025 XI: < 2024R1.2 Nagios addresses this vulnerability as "Nagios XI was vulnerable to command injection via the Docker Wizard" and as a part of "Improved validation in Docker Wizard and mitigated NULL poisoning vulnerability on systems with older PHP distributions." Update reference ↗
CVE-2020-36867 30 Oct 2025 < 5.7.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2021-47689 30 Oct 2025 < 5.8.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2021-47691 30 Oct 2025 < 5.8.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-50584 30 Oct 2025 < 5.8.8 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-36861 30 Oct 2025 < 5.7.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2021-47690 30 Oct 2025 < 5.8.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-36860 30 Oct 2025 < 5.7.4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-50585 30 Oct 2025 < 5.8.9 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-36859 30 Oct 2025 < 5.7.4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2021-47693 30 Oct 2025 < 5.8.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2021-47694 30 Oct 2025 < 5.8.6 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2013-10073 30 Oct 2025 < 2012R1.6 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2013-10072 30 Oct 2025 < 2012R1.6 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-36857 30 Oct 2025 < 5.6.14 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2012-10063 30 Oct 2025 < 2012R1.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-36856 30 Oct 2025 < 5.6.14 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-14002 30 Oct 2025 XI: < 2024R1.1.4 Nagios addresses this vulnerability as "Nagios XI is vulnerable to an authenticated Local File Inclusion attack via Nagvis." and as part of "Fixed both XSS in Executive Summary report and ajaxhelper endpoint that was too open." Update reference ↗
CVE-2025-34284 30 Oct 2025 XI: < 2024R2 Nagios addresses this vulnerability as "Nagios XI was vulnerable to authenticated command injection via the WinRM plugin" and "Fixed security issue in WinRM wizard." Update reference ↗
CVE-2024-13995 30 Oct 2025 XI: 2024R1.1 < 2024R1.1.2, 2024R1.1.1 < 2024R1.1.2, < 2024R1.1.2 Nagios addresses this vulnerability as "Nagios XI 2024R1.1 and 2024R1.1.1 will leak user account information (including API keys and hashed passwords) to authenticated users." Update reference ↗
CVE-2025-34283 30 Oct 2025 XI: < 2024R1.4.2 Nagios addresses this vulnerability as "Nagios XI would sometimes reveal API keys to users that were not authorized for API access" and "Fixed an issue where an API key was shown to users without API access in Neptune themes." Update reference ↗
CVE-2024-13994 30 Oct 2025 XI: < 2024R1.1.2 Nagios addresses this vulnerability as "Nagios XI versions 2024R1.1.1 and earlier are missing authorization controls when "Allow Insecure Logins" is enabled, allowing any user to create a valid login credential for other users" and "Fixed an issue where any user could modify an insecure login ticket." Update reference ↗
CVE-2024-13999 30 Oct 2025 XI: < 2024R1.1.3 Nagios addresses this vulnerability as "Nagios XI could, under certain circumstances, leak the server's AD/LDAP token to an authenticated user." Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.