Librenms
by Librenms
Source repositories
CVEs (122)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-10670 | Med | 0.40 | 6.1 | 0.01 | Sep 9, 2019 | An issue was discovered in LibreNMS through 1.47. Many of the scripts rely on the function mysqli_escape_real_string for filtering data. However, this is particularly ineffective when returning user supplied input in an HTML or a JavaScript context, resulting in unsafe data… | ||
| CVE-2026-84192 | Hig | 0.39 | 7.1 | 0.00 | Sep 1, 2026 | LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls a monitored network device can inject arbitrary JavaScript through SNMP interface… | ||
| CVE-2022-0588 | Hig | 0.39 | 7.1 | 0.01 | Feb 15, 2022 | Missing Authorization in Packagist librenms/librenms prior to 22.2.0. | ||
| CVE-2022-0580 | Hig | 0.39 | 7.1 | 0.01 | Feb 14, 2022 | Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0. | ||
| CVE-2023-5591 | Med | 0.37 | 6.5 | 0.22 | Oct 16, 2023 | SQL Injection in GitHub repository librenms/librenms prior to 23.10.0. | ||
| CVE-2022-4067 | Med | 0.36 | 5.4 | 0.94 | Nov 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. | ||
| CVE-2022-3562 | Med | 0.36 | 5.4 | 0.94 | Nov 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. | ||
| CVE-2025-23201 | Med | 0.35 | 5.4 | 0.00 | Jan 16, 2025 | librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to Cross-site Scripting (XSS) on the parameters:`/addhost` -> param: community. Librenms versions up to 24.10.1 allow remote attackers to inject malicious scripts. When a user… | ||
| CVE-2022-0587 | Med | 0.35 | 6.5 | 0.01 | Feb 15, 2022 | Improper Authorization in Packagist librenms/librenms prior to 22.2.0. | ||
| CVE-2020-15873 | Med | 0.35 | 6.5 | 0.02 | Jul 21, 2020 | In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php. | ||
| CVE-2019-10667 | Med | 0.35 | 5.3 | 0.01 | Sep 9, 2019 | An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and disclose local file paths. | ||
| CVE-2019-15230 | Med | 0.35 | 5.4 | 0.01 | Aug 28, 2019 | LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an… | ||
| CVE-2025-47931 | Med | 0.34 | 6.1 | 0.12 | May 17, 2025 | LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scripting (XSS) Vulnerability in the `group name` parameter of the `http://localhost/poller/groups` form. This vulnerability allows attackers to inject… | ||
| CVE-2023-48295 | Med | 0.34 | 6.3 | 0.01 | Nov 17, 2023 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. Affected versions are subject to a cross site scripting (XSS) vulnerability in the device group popups. This issue has been… | ||
| CVE-2023-4347 | Med | 0.34 | 5.4 | 0.70 | Aug 15, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0. | ||
| CVE-2026-84191 | Med | 0.33 | 6.1 | 0.00 | Sep 1, 2026 | LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered without sanitization. Attackers controlling a monitored network device… | ||
| CVE-2026-26987 | Med | 0.33 | 6.1 | 0.00 | Feb 20, 2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to Reflected XSS attacks via email field. This issue has been fixed in version 26.2.0. | ||
| CVE-2025-65013 | Med | 0.33 | 6.2 | 0.00 | Nov 18, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scripting (XSS) vulnerability was identified in the LibreNMS application at the /maps/nodeimage endpoint. The Image Name parameter is reflected in the… | ||
| CVE-2025-62365 | Med | 0.33 | 6.1 | 0.00 | Oct 13, 2025 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in `report_this` function in `librenms/includes/functions.php`. The `report_this` function had improper filtering (`htmlentities` function was incorrectly use in… | ||
| CVE-2023-5060 | Med | 0.33 | 6.1 | 0.01 | Sep 19, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1. |
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in LibreNMS through 1.47. Many of the scripts rely on the function mysqli_escape_real_string for filtering data. However, this is particularly ineffective when returning user supplied input in an HTML or a JavaScript context, resulting in unsafe data…
- risk 0.39cvss 7.1epss 0.00
LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls a monitored network device can inject arbitrary JavaScript through SNMP interface…
- risk 0.39cvss 7.1epss 0.01
Missing Authorization in Packagist librenms/librenms prior to 22.2.0.
- risk 0.39cvss 7.1epss 0.01
Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.
- risk 0.37cvss 6.5epss 0.22
SQL Injection in GitHub repository librenms/librenms prior to 23.10.0.
- risk 0.36cvss 5.4epss 0.94
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
- risk 0.36cvss 5.4epss 0.94
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
- risk 0.35cvss 5.4epss 0.00
librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to Cross-site Scripting (XSS) on the parameters:`/addhost` -> param: community. Librenms versions up to 24.10.1 allow remote attackers to inject malicious scripts. When a user…
- risk 0.35cvss 6.5epss 0.01
Improper Authorization in Packagist librenms/librenms prior to 22.2.0.
- risk 0.35cvss 6.5epss 0.02
In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and disclose local file paths.
- risk 0.35cvss 5.4epss 0.01
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an…
- risk 0.34cvss 6.1epss 0.12
LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scripting (XSS) Vulnerability in the `group name` parameter of the `http://localhost/poller/groups` form. This vulnerability allows attackers to inject…
- risk 0.34cvss 6.3epss 0.01
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. Affected versions are subject to a cross site scripting (XSS) vulnerability in the device group popups. This issue has been…
- risk 0.34cvss 5.4epss 0.70
Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0.
- risk 0.33cvss 6.1epss 0.00
LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered without sanitization. Attackers controlling a monitored network device…
- risk 0.33cvss 6.1epss 0.00
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to Reflected XSS attacks via email field. This issue has been fixed in version 26.2.0.
- risk 0.33cvss 6.2epss 0.00
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scripting (XSS) vulnerability was identified in the LibreNMS application at the /maps/nodeimage endpoint. The Image Name parameter is reflected in the…
- risk 0.33cvss 6.1epss 0.00
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in `report_this` function in `librenms/includes/functions.php`. The `report_this` function had improper filtering (`htmlentities` function was incorrectly use in…
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.
Page 3 of 7