Nagios
XI
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
Official registry publication history is available at xi, but registry activity is not a publisher support boundary.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2025-34135 | 30 Oct 2025 | XI: < 2024R1.4.2 | Nagios addresses this vulnerability as "Nagios XI had some Systemd unit files with permission sets that were too permissive" and "Fixed a permissions insecurity for nagios.service (removed execute permissions)." | Update reference ↗ |
| CVE-2021-47700 | 30 Oct 2025 | < 5.8.7 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2024-14006 | 30 Oct 2025 | XI: < 2024R1.2.2 | Nagios addresses this vulnerability as "Nagios XI was vulnerable to a host header injection attack" and as a part of "Fixed a vulnerability to host header injection attacks." | Update reference ↗ |
| CVE-2018-25122 | 30 Oct 2025 | < 5.4.13 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2024-14005 | 30 Oct 2025 | XI: < 2024R1.2 | Nagios addresses this vulnerability as "Nagios XI was vulnerable to command injection via the Docker Wizard" and as a part of "Improved validation in Docker Wizard and mitigated NULL poisoning vulnerability on systems with older PHP distributions." | Update reference ↗ |
| CVE-2020-36867 | 30 Oct 2025 | < 5.7.3 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2021-47689 | 30 Oct 2025 | < 5.8.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2021-47691 | 30 Oct 2025 | < 5.8.2 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2022-50584 | 30 Oct 2025 | < 5.8.8 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-36861 | 30 Oct 2025 | < 5.7.5 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2021-47690 | 30 Oct 2025 | < 5.8.2 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-36860 | 30 Oct 2025 | < 5.7.4 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2022-50585 | 30 Oct 2025 | < 5.8.9 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-36859 | 30 Oct 2025 | < 5.7.4 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2021-47693 | 30 Oct 2025 | < 5.8.5 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2021-47694 | 30 Oct 2025 | < 5.8.6 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2013-10073 | 30 Oct 2025 | < 2012R1.6 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2013-10072 | 30 Oct 2025 | < 2012R1.6 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-36857 | 30 Oct 2025 | < 5.6.14 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2012-10063 | 30 Oct 2025 | < 2012R1.3 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-36856 | 30 Oct 2025 | < 5.6.14 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2024-14002 | 30 Oct 2025 | XI: < 2024R1.1.4 | Nagios addresses this vulnerability as "Nagios XI is vulnerable to an authenticated Local File Inclusion attack via Nagvis." and as part of "Fixed both XSS in Executive Summary report and ajaxhelper endpoint that was too open." | Update reference ↗ |
| CVE-2025-34284 | 30 Oct 2025 | XI: < 2024R2 | Nagios addresses this vulnerability as "Nagios XI was vulnerable to authenticated command injection via the WinRM plugin" and "Fixed security issue in WinRM wizard." | Update reference ↗ |
| CVE-2024-13995 | 30 Oct 2025 | XI: 2024R1.1 < 2024R1.1.2, 2024R1.1.1 < 2024R1.1.2, < 2024R1.1.2 | Nagios addresses this vulnerability as "Nagios XI 2024R1.1 and 2024R1.1.1 will leak user account information (including API keys and hashed passwords) to authenticated users." | Update reference ↗ |
| CVE-2025-34283 | 30 Oct 2025 | XI: < 2024R1.4.2 | Nagios addresses this vulnerability as "Nagios XI would sometimes reveal API keys to users that were not authorized for API access" and "Fixed an issue where an API key was shown to users without API access in Neptune themes." | Update reference ↗ |
| CVE-2024-13994 | 30 Oct 2025 | XI: < 2024R1.1.2 | Nagios addresses this vulnerability as "Nagios XI versions 2024R1.1.1 and earlier are missing authorization controls when "Allow Insecure Logins" is enabled, allowing any user to create a valid login credential for other users" and "Fixed an issue where any user could modify an insecure login ticket." | Update reference ↗ |
| CVE-2024-13999 | 30 Oct 2025 | XI: < 2024R1.1.3 | Nagios addresses this vulnerability as "Nagios XI could, under certain circumstances, leak the server's AD/LDAP token to an authenticated user." | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.