VYPR

Librenms

by Librenms

Source repositories

CVEs (122)

  • CVE-2020-15877HigJul 21, 2020
    risk 0.50cvss 8.8epss 0.02

    An issue was discovered in LibreNMS before 1.65.1. It has insufficient access control for normal users because of "'guard' => 'admin'" instead of "'middleware' => ['can:admin']" in routes/web.php.

  • CVE-2018-20678HigMar 28, 2019
    risk 0.50cvss 8.8epss 0.01

    LibreNMS through 1.47 allows SQL injection via the html/ajax_table.php sort[hostname] parameter, exploitable by authenticated users during a search.

  • CVE-2026-84194HigSep 1, 2026
    risk 0.49cvss —epss 0.01

    LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an authenticated OS command injection vulnerability in libvirt discovery. When libvirt support is enabled (enable_libvirt=true), the device hostname ($this->getDevice()->hostname) is concatenated into shell…

  • CVE-2026-55182HigAug 26, 2026
    risk 0.49cvss —epss 0.01

    LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection because the signal-cli path and the Recipient field of an alert transport entry are insufficiently escaped before being passed to an exec…

  • CVE-2026-80214HigAug 26, 2026
    risk 0.49cvss —epss 0.00

    LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can execute arbitrary code on the host server.

  • CVE-2019-12464HigSep 9, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in LibreNMS 1.50.1. An authenticated user can perform a directory traversal attack against the /pdf.php file with a partial filename in the report parameter, to cause local file inclusion resulting in code execution.

  • CVE-2024-49754HigNov 15, 2024
    risk 0.47cvss 7.5epss 0.71

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the API-Access page allows authenticated users to inject arbitrary JavaScript through the "token" parameter when creating a new API token. This…

  • CVE-2026-84189HigSep 1, 2026
    risk 0.46cvss 8.1epss 0.00

    LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page without applying htmlspecialchars(). An administrator who points the Oxidized URL at…

  • CVE-2020-36947HigJan 27, 2026
    risk 0.46cvss 7.1epss 0.00

    LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract database information. Attackers can exploit the vulnerability by manipulating the 'sort' parameter with crafted SQL injection…

  • CVE-2024-47525HigOct 1, 2024
    risk 0.44cvss 7.5epss 0.30

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Rules" feature allows authenticated users to inject arbitrary JavaScript through the "Title" field. This vulnerability can lead to the…

  • CVE-2026-30480MedApr 14, 2026
    risk 0.42cvss 6.5epss 0.00

    A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesystem via path traversal sequences in the nfsen parameter.

  • CVE-2025-54138HigJul 22, 2025
    risk 0.42cvss 7.5epss 0.01

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. LibreNMS versions 25.6.0 and below contain an architectural vulnerability in the ajax_form.php endpoint that permits Remote…

  • CVE-2024-47527HigOct 1, 2024
    risk 0.42cvss 7.5epss 0.01

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Device Dependencies" feature allows authenticated users to inject arbitrary JavaScript through the device name ("hostname" parameter). This…

  • CVE-2024-47523HigOct 1, 2024
    risk 0.42cvss 7.5epss 0.01

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Transports" feature allows authenticated users to inject arbitrary JavaScript through the "Details" section (which contains multiple fields…

  • CVE-2024-32479HigApr 22, 2024
    risk 0.42cvss 7.1epss 0.34

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to version 24.4.0, there is improper sanitization on the `Service` template name, which can lead to stored Cross-site Scripting. Version 24.4.0 fixes this vulnerability.

  • CVE-2024-32480HigApr 22, 2024
    risk 0.41cvss 7.2epss 0.20

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Versions prior to 24.4.0 are vulnerable to SQL injection. The `order` parameter is obtained from `$request`. After performing a string check, the value is directly incorporated into an SQL statement and…

  • CVE-2024-32461HigApr 22, 2024
    risk 0.41cvss 7.1epss 0.19

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A SQL injection vulnerability in POST /search/search=packages in LibreNMS prior to version 24.4.0 allows a user with global read privileges to execute SQL commands via the package parameter. With this…

  • CVE-2026-84190HigSep 1, 2026
    risk 0.40cvss 7.2epss 0.01

    LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the snmpget configuration parameter is passed to shell_exec() without proper validation. An authenticated administrator can modify the snmpget configuration to point to a…

  • CVE-2026-6204HigApr 13, 2026
    risk 0.40cvss 7.2epss 0.08

    LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could result in compromise of the…

  • CVE-2024-47524HigOct 1, 2024
    risk 0.40cvss 7.2epss 0.01

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can create a Device Groups, the application did not properly sanitize the user input in the Device Groups name, when user see the detail of the Device Group, if java script code is…

Page 2 of 7