Thomas Vincent
10 exploits
Active since Jun 2026
Cacti: Session Fixation via missing session_regenerate_id() after login
CVSS 5.4
Cacti: Arbitrary File Read via Path Traversal in Report `format_file` Parameter
CVSS 6.5
Cacti: RRDtool metric shift via LC_NUMERIC locale comma decimal formatting
CVSS 2.9
Cacti has a Reflected XSS Vulnerability via html_auth_footer
CVSS 6.1
Cacti: Reflected XSS via tab parameter in auth_profile.php JavaScript context
CVSS 6.1
Cacti: Unauthenticated RCE on Graph Image
CVSS 9.8
Cacti has SQL Injection via rfilter parameter in RLIKE clauses
CVSS 9.8
Cacti: Stored SQL Injection via graph_name_regexp in Reports feature
CVSS 7.6
Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php
CVSS 9.8
Cacti: Command Injection via escape_command() no-op in RRDtool execution
CVSS 9.8