Librenms
by Librenms
Source repositories
CVEs (122)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-4978 | Med | 0.33 | 6.1 | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0. | ||
| CVE-2022-3561 | Med | 0.33 | 6.1 | 0.01 | Nov 20, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0. | ||
| CVE-2022-3516 | Med | 0.33 | 6.1 | 0.00 | Nov 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. | ||
| CVE-2022-36746 | Med | 0.33 | 6.1 | 0.01 | Aug 30, 2022 | LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php. | ||
| CVE-2022-36745 | Med | 0.33 | 6.1 | 0.01 | Aug 30, 2022 | LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php. | ||
| CVE-2022-29711 | Med | 0.33 | 6.1 | 0.01 | Jun 2, 2022 | LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogController.php. | ||
| CVE-2022-0576 | Med | 0.33 | 6.1 | 0.01 | Feb 14, 2022 | Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0. | ||
| CVE-2021-43324 | Med | 0.33 | 6.1 | 0.01 | Nov 3, 2021 | LibreNMS through 21.10.2 allows XSS via a widget title. | ||
| CVE-2024-53457 | Med | 0.32 | 5.4 | 0.45 | Dec 5, 2024 | A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter. | ||
| CVE-2022-4069 | Med | 0.32 | 4.8 | 0.93 | Nov 20, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0. | ||
| CVE-2017-16759 | Med | 0.32 | 5.9 | 0.02 | Nov 9, 2017 | The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php. | ||
| CVE-2026-84193 | Med | 0.31 | — | 0.00 | Sep 1, 2026 | LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or… | ||
| CVE-2026-49870 | Med | 0.31 | 5.9 | 0.00 | Aug 19, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or attempt counter, allowing an attacker with valid credentials to submit unlimited TOTP guesses against the three accepted codes created by config/google2fa.php… | ||
| CVE-2022-4068 | Med | 0.31 | 5.4 | 0.36 | Nov 20, 2022 | A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attack that enables an attacker with a low privilege user to… | ||
| CVE-2025-62411 | Med | 0.30 | 5.5 | 0.13 | Oct 16, 2025 | LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When an administrator creates a new Alert Transport, the value of the Transport… | ||
| CVE-2025-55296 | Med | 0.30 | 5.5 | 0.12 | Aug 18, 2025 | librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. This allows a user with the admin role to inject malicious JavaScript, which will be… | ||
| CVE-2025-65093 | Med | 0.29 | 5.5 | 0.04 | Nov 18, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application at the /ajax_output.php endpoint. The hostname parameter is interpolated directly… | ||
| CVE-2026-45694 | Med | 0.28 | 5.4 | 0.00 | Aug 26, 2026 | LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected into the page title without adequate… | ||
| CVE-2026-27016 | Med | 0.28 | 5.4 | 0.00 | Feb 20, 2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype)… | ||
| CVE-2023-4982 | Med | 0.28 | 5.4 | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0. |
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.
- risk 0.33cvss 6.1epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
- risk 0.33cvss 6.1epss 0.01
LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php.
- risk 0.33cvss 6.1epss 0.01
LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php.
- risk 0.33cvss 6.1epss 0.01
LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogController.php.
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0.
- risk 0.33cvss 6.1epss 0.01
LibreNMS through 21.10.2 allows XSS via a widget title.
- risk 0.32cvss 5.4epss 0.45
A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.
- risk 0.32cvss 4.8epss 0.93
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.
- risk 0.32cvss 5.9epss 0.02
The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.
- risk 0.31cvss —epss 0.00
LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or…
- risk 0.31cvss 5.9epss 0.00
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or attempt counter, allowing an attacker with valid credentials to submit unlimited TOTP guesses against the three accepted codes created by config/google2fa.php…
- risk 0.31cvss 5.4epss 0.36
A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attack that enables an attacker with a low privilege user to…
- risk 0.30cvss 5.5epss 0.13
LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When an administrator creates a new Alert Transport, the value of the Transport…
- risk 0.30cvss 5.5epss 0.12
librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. This allows a user with the admin role to inject malicious JavaScript, which will be…
- risk 0.29cvss 5.5epss 0.04
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application at the /ajax_output.php endpoint. The hostname parameter is interpolated directly…
- risk 0.28cvss 5.4epss 0.00
LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected into the page title without adequate…
- risk 0.28cvss 5.4epss 0.00
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype)…
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0.
Page 4 of 7