
CVE-2025-45160 A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid format is uploaded, the application reflects th… https://www.cve.org/CVERecord?id=CVE-2025-45160
Post summary
The text reports an HTML injection vulnerability in Cacti <=1.2.29's file upload, where uploading files with an invalid format can result in reflected HTML injection; no PoC, exploit or mitigation is provided.

