Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Not in CISA KEV

CVE-2020-27988

CVE-2020-27988 is a Cross-site Scripting (XSS) vulnerability. EPSS puts its 30-day exploitation probability at 91.3% (100th percentile). No vendor fix is recorded yet; mitigation options are listed below.

Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).

Published
Nov 16, 2020
Updated
Aug 4, 2024
Affected
1 product
Patched
See advisory
Exploits
None indexed
Exploitation data as of Sep 28, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

EPSS Exploitation Probability

via FIRST.org ↗
91.3%probability of exploitation in next 30 days
Very High Risk0.00%
Lower risk than most CVEs100th percentile — riskier than 100% of all scored CVEsHighest risk

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Description

Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).

Affected Products

1 product · 1 configurations
Application
nagios xinagios
< 5.7.5
range

Detection & mitigation playbook

Vulnerability
  1. Detect

    Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).

  2. Remediation status

    No fixed release is recorded for CVE-2020-27988 yet. Track the upstream advisory, and apply the exposure-reduction steps below in the meantime.

  3. Mitigate without a patch

    Escape or sanitise the affected output on the server side rather than relying on client-side filtering, and add a Content-Security-Policy that blocks inline script execution so injected markup cannot run even if it reaches the page.

Frequently Asked Questions

Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
O3 Security · Impact-Aware SCA

Is CVE-2020-27988 in your dependencies?

Find it across , including transitive dependencies.

CVE-2020-27988: XSS | O3 Security