Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel.
https://github.com/Live-Hack-CVE/CVE-2022-38251
https://www.nagios.com/downloads/nagios-xi/change-log/#5.8.7