Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.
{ "binaries": [ { "binary_name": "nagios3", "binary_version": "3.5.1.dfsg-2.1ubuntu1.3" }, { "binary_name": "nagios3-cgi", "binary_version": "3.5.1.dfsg-2.1ubuntu1.3" }, { "binary_name": "nagios3-common", "binary_version": "3.5.1.dfsg-2.1ubuntu1.3" }, { "binary_name": "nagios3-core", "binary_version": "3.5.1.dfsg-2.1ubuntu1.3" } ] }
{ "binaries": [ { "binary_name": "nagios3", "binary_version": "3.5.1.dfsg-2.1ubuntu8" }, { "binary_name": "nagios3-cgi", "binary_version": "3.5.1.dfsg-2.1ubuntu8" }, { "binary_name": "nagios3-common", "binary_version": "3.5.1.dfsg-2.1ubuntu8" }, { "binary_name": "nagios3-core", "binary_version": "3.5.1.dfsg-2.1ubuntu8" } ] }