CVE Tools

Munin

10 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Munin, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Munin CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Munin CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 10 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical110%
  • High220%
  • Medium660%
  • Low110%

Latest CVEs

The 10 most recently published vulnerabilities affecting Munin.

  1. CVE-2019-3694Local privilege escalation from munin to root in the packaging of munin7.7
  2. CVE-2017-6188Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.5.5
  3. CVE-2013-6048The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the munin-html process...5.0
  4. CVE-2013-6359Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses "multigraph" as a multigraph service name.4.3
  5. CVE-2012-3513munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via the logdir command.9.3
  6. CVE-2012-3512Munin before 2.0.6 stores plugin state files that run as root in the same group-writable directory as non-root plugins, which allows local users to execute arbitrary code by replacing a state file,...7.2
  7. CVE-2012-2147munin-cgi-graph in Munin 2.0 rc4 allows remote attackers to cause a denial of service (disk or memory consumption) via many image requests with large values in the (1) size_x or (2) size_y parameters.5.0
  8. CVE-2012-2103The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.1.2
  9. CVE-2012-2104cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might allow user-assisted remote attackers to inject terminal emulator escape seque...6.8
  10. CVE-2012-4678munin-cgi-graph for Munin 2.0 rc4 does not delete temporary files, which allows remote attackers to cause a denial of service (disk consumption) via many requests to an image with unique parameters.5.0

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store