Beuc

1 exploit Active since Feb 2025
CVE-2025-26520 WRITEUP HIGH WRITEUP
Cacti < 1.2.29 - SQL Injection via Graph Template Parameter
Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists because of an incomplete fix for CVE-2024-54146.
CVSS 7.6