Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can supply a malicious payload which is stored by the application and later rendered in the context of other users. When a victim views the affected page the injected script executes in the victim's browser context.
Use CWE-79, Nagios vendor hub and Network Analyzer product page to widen CVE-2025-34278 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-28925, CVE-2025-34280 and CVE-2025-28059 for nearby disclosures in the same product family. Additional editorial context is available in Why “Low” and “Medium” CVEs Still Breach Networks.