VYPR

Librenms

by Librenms

Source repositories

CVEs (107)

  • CVE-2019-15230MedAug 28, 2019
    risk 0.35cvss 5.4epss 0.01

    LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an…

  • CVE-2023-48295MedNov 17, 2023
    risk 0.34cvss 6.3epss 0.01

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. Affected versions are subject to a cross site scripting (XSS) vulnerability in the device group popups. This issue has been…

  • CVE-2026-26987MedFeb 20, 2026
    risk 0.33cvss 6.1epss 0.00

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to Reflected XSS attacks via email field. This issue has been fixed in version 26.2.0.

  • CVE-2025-65013MedNov 18, 2025
    risk 0.33cvss 6.2epss 0.00

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scripting (XSS) vulnerability was identified in the LibreNMS application at the /maps/nodeimage endpoint. The Image Name parameter is reflected in the…

  • CVE-2025-62365MedOct 13, 2025
    risk 0.33cvss 6.1epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in `report_this` function in `librenms/includes/functions.php`. The `report_this` function had improper filtering (`htmlentities` function was incorrectly use in…

  • CVE-2025-47931MedMay 17, 2025
    risk 0.33cvss 6.1epss 0.00

    LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scripting (XSS) Vulnerability in the `group name` parameter of the `http://localhost/poller/groups` form. This vulnerability allows attackers to inject…

  • CVE-2023-5060MedSep 19, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.

  • CVE-2023-4978MedSep 15, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.

  • CVE-2023-4347MedAug 15, 2023
    risk 0.33cvss 5.4epss 0.67

    Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0.

  • CVE-2022-3561MedNov 20, 2022
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.

  • CVE-2022-3516MedNov 20, 2022
    risk 0.33cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.

  • CVE-2022-36746MedAug 30, 2022
    risk 0.33cvss 6.1epss 0.00

    LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php.

  • CVE-2022-36745MedAug 30, 2022
    risk 0.33cvss 6.1epss 0.00

    LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php.

  • CVE-2022-29711MedJun 2, 2022
    risk 0.33cvss 6.1epss 0.01

    LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogController.php.

  • CVE-2022-0576MedFeb 14, 2022
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0.

  • CVE-2021-43324MedNov 3, 2021
    risk 0.33cvss 6.1epss 0.01

    LibreNMS through 21.10.2 allows XSS via a widget title.

  • CVE-2022-4069MedNov 20, 2022
    risk 0.32cvss 4.8epss 0.93

    Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.

  • CVE-2017-16759MedNov 9, 2017
    risk 0.32cvss 5.9epss 0.02

    The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.

  • CVE-2024-53457MedDec 5, 2024
    risk 0.31cvss 5.4epss 0.42

    A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.

  • CVE-2022-4068MedNov 20, 2022
    risk 0.31cvss 5.4epss 0.34

    A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attack that enables an attacker with a low privilege user to…

Page 3 of 6