netbox CVE Vulnerabilities & Metrics

Focus on netbox vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About netbox Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with netbox. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total netbox CVEs: 39
Earliest CVE date: 31 Dec 2020, 20:15 UTC
Latest CVE date: 09 Jul 2024, 18:15 UTC

Latest CVE reference: CVE-2024-40742

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 18

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -10.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -10.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical netbox CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.17

Max CVSS: 3.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 39
4.0-6.9 0
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS netbox CVEs

These are the five CVEs with the highest CVSS scores for netbox, sorted by severity first and recency.

All CVEs for netbox

CVE-2024-40742 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the circuit ID parameter at /circuits/circuits/add.

CVE-2024-40741 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the circuit ID parameter at /circuits/circuits/{id}/edit/.

CVE-2024-40740 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-feeds/{id}/edit/.

CVE-2024-40739 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-feeds/add.

CVE-2024-40738 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/console-ports/{id}/edit/.

CVE-2024-40737 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/console-ports/add.

CVE-2024-40736 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-outlets/add.

CVE-2024-40735 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-outlets/{id}/edit/.

CVE-2024-40734 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/front-ports/add/.

CVE-2024-40733 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/front-ports/{id}/edit/.

CVE-2024-40732 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/rear-ports/add/.

CVE-2024-40731 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/rear-ports/{id}/edit/.

CVE-2024-40730 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/interfaces/{id}/edit/.

CVE-2024-40729 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/interfaces/add/.

CVE-2024-40728 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/console-server-ports/{id}/edit/.

CVE-2024-40727 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/console-server-ports/add/.

CVE-2024-40726 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-ports/{id}/edit/.

CVE-2024-38972 netbox vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-ports/add/.

CVE-2024-0948 netbox vulnerability CVSS: 3.3 26 Jan 2024, 22:15 UTC

** DISPUTED ** A vulnerability, which was classified as problematic, has been found in NetBox up to 3.7.0. This issue affects some unknown processing of the file /core/config-revisions of the component Home Page Configuration. The manipulation with the input <<h1 onload=alert(1)>>test</h1> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The associated identifier of this vulnerability is VDB-252191. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-36234 netbox vulnerability CVSS: 0 20 Sep 2023, 22:15 UTC

Cross Site Scripting (XSS) vulnerability in Netbox 3.5.1, allows attackers to execute arbitrary code via Name field in device-roles/add function.

CVE-2023-37625 netbox vulnerability CVSS: 0 10 Aug 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates.

CVE-2023-34565 netbox vulnerability CVSS: 0 14 Jun 2023, 21:15 UTC

Netbox 3.5.1 is vulnerable to Cross Site Scripting (XSS) in the "Create Wireless LAN Groups" function.

CVE-2023-33800 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create Regions (/dcim/regions/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2023-33799 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create Contacts (/tenancy/contacts/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2023-33798 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create Rack (/dcim/rack/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2023-33797 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create Sites (/dcim/sites/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2023-33796 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, granting them access to sensitive data stored in the database. NOTE: the vendor disputes this because the reporter's only query was for the schema of the API, which is public; queries for database objects would have been denied.

CVE-2023-33795 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create Contact Roles (/tenancy/contact-roles/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2023-33794 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create Tenants (/tenancy/tenants/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2023-33793 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create Power Panels (/dcim/power-panels/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2023-33792 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create Site Groups (/dcim/site-groups/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2023-33791 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create Provider Accounts (/circuits/provider-accounts/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2023-33790 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create Locations (/dcim/locations/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2023-33789 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create Contact Groups (/tenancy/contact-groups/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2023-33788 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create Providers (/circuits/providers/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2023-33787 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create Tenant Groups (/tenancy/tenant-groups/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2023-33786 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create Circuit Types (/circuits/circuit-types/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2023-33785 netbox vulnerability CVSS: 0 24 May 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create Rack Roles (/dcim/rack-roles/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVE-2019-25011 netbox vulnerability CVSS: 3.5 31 Dec 2020, 20:15 UTC

NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as demonstrated by /dcim/sites/add/ comments.