S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
\" to successfully execute the…","isAccessibleForFree":true,"inLanguage":"en","isPartOf":{"@id":"https://s4e.io/#website"},"breadcrumb":{"@id":"https://s4e.io/cve/CVE-2021-26247#breadcrumb"},"sameAs":"https://nvd.nist.gov/vuln/detail/CVE-2021-26247","identifier":"CVE-2021-26247","about":{"@type":"Thing","name":"CVE-2021-26247 (cacti)","identifier":"CVE-2021-26247","description":"As an unauthenticated remote user, visit \"http:///auth_changepassword.php?ref=\" to successfully execute the JavaScript payload present in the \"ref\" URL parameter.","sameAs":"https://nvd.nist.gov/vuln/detail/CVE-2021-26247"}},{"@type":"BreadcrumbList","@id":"https://s4e.io/cve/CVE-2021-26247#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://s4e.io"},{"@type":"ListItem","position":2,"name":"CVE","item":"https://s4e.io/cve/CVE-2021-26247"},{"@type":"ListItem","position":3,"name":"CVE-2021-26247","item":"https://s4e.io/cve/CVE-2021-26247"}]}]}
CVE

CVE-2021-26247

6.1
CVSS
Description

As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
cacti
Updated Sep 18, 2026View on NVD →
S4E scanner

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →