Total vulnerabilities in the database
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
CVSS v3:
CVSS v2:
CWEs:
OWASP TOP 10: