Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3884-1 | cacti security update |
EUVD |
EUVD-2024-29341 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.php` file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. There is a file inclusion issue with the `api_plugin_hook()` function in the `lib/plugin.php` file, which reads the plugin_hooks and plugin_config tables in database. The read data is directly used to concatenate the file path which is used for file inclusion. Version 1.2.27 contains a patch for the issue. |
Ubuntu USN |
USN-6969-1 | Cacti vulnerabilities |
Wed, 17 Dec 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Tue, 16 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Tue, 04 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 13 Feb 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cacti RCE vulnerability by file include in lib/plugin.php | Cacti RCE vulnerability by file include in lib/plugin.php |
Wed, 18 Dec 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fedoraproject
Fedoraproject fedora |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fedoraproject
Fedoraproject fedora |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-16T18:13:18.089Z
Reserved: 2024-04-03T17:55:32.647Z
Link: CVE-2024-31459
Updated: 2025-11-04T16:12:00.875Z
Status : Modified
Published: 2024-05-14T15:25:26.110
Modified: 2025-11-04T17:15:50.990
Link: CVE-2024-31459
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN