Librenms
by Librenms
Source repositories
CVEs (107)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-62411 | Med | 0.30 | 5.5 | 0.12 | Oct 16, 2025 | LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When an administrator creates a new Alert Transport, the value of the Transport… | ||
| CVE-2025-55296 | Med | 0.30 | 5.5 | 0.12 | Aug 18, 2025 | librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. This allows a user with the admin role to inject malicious JavaScript, which will be… | ||
| CVE-2025-65093 | Med | 0.29 | 5.5 | 0.04 | Nov 18, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application at the /ajax_output.php endpoint. The hostname parameter is interpolated directly… | ||
| CVE-2026-27016 | Med | 0.28 | 5.4 | 0.00 | Feb 20, 2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype)… | ||
| CVE-2023-4982 | Med | 0.28 | 5.4 | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0. | ||
| CVE-2023-4981 | Med | 0.28 | 5.4 | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0. | ||
| CVE-2023-4980 | Med | 0.28 | 5.4 | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0. | ||
| CVE-2023-4979 | Med | 0.28 | 5.4 | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0. | ||
| CVE-2023-4977 | Med | 0.28 | 5.4 | 0.00 | Sep 15, 2023 | Code Injection in GitHub repository librenms/librenms prior to 23.9.0. | ||
| CVE-2022-3231 | Med | 0.28 | 5.4 | 0.01 | Sep 17, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0. | ||
| CVE-2022-0589 | Med | 0.28 | 5.4 | 0.01 | Feb 15, 2022 | Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0. | ||
| CVE-2022-0575 | Med | 0.28 | 5.4 | 0.01 | Feb 14, 2022 | Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0. | ||
| CVE-2024-50352 | Med | 0.27 | 4.8 | 0.37 | Nov 15, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "name" parameter when adding… | ||
| CVE-2023-46745 | Med | 0.27 | 5.3 | 0.01 | Nov 17, 2023 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions the login method has no rate limit. An attacker may be able to leverage this vulnerability to gain… | ||
| CVE-2026-49870 | med | 0.26 | — | — | Jun 23, 2026 | ### Impact `POST /two-factor` had no rate limiting, lockout, or attempt counter. An attacker with valid credentials can submit unlimited TOTP guesses. The TOTP implementation accepts the current code plus one step on either side (`config/google2fa.php window=1`), so at any… | ||
| CVE-2025-23200 | Med | 0.25 | 4.6 | 0.31 | Jan 16, 2025 | librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameter: `ajax_form.php` -> param: state. Librenms versions up to 24.10.1 allow remote attackers to inject malicious scripts. When a user views or… | ||
| CVE-2026-2728 | Med | 0.24 | 4.8 | 0.00 | Apr 13, 2026 | LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against other users with access to the… | ||
| CVE-2026-26992 | Med | 0.24 | 4.8 | 0.00 | Feb 20, 2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the port group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a port group, an HTTP… | ||
| CVE-2026-26991 | Med | 0.24 | 4.8 | 0.00 | Feb 20, 2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the device group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a device group, an… | ||
| CVE-2024-52526 | Med | 0.24 | 4.8 | 0.00 | Nov 15, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" tab of the Device page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when adding a service to… |
- risk 0.30cvss 5.5epss 0.12
LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When an administrator creates a new Alert Transport, the value of the Transport…
- risk 0.30cvss 5.5epss 0.12
librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. This allows a user with the admin role to inject malicious JavaScript, which will be…
- risk 0.29cvss 5.5epss 0.04
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application at the /ajax_output.php endpoint. The hostname parameter is interpolated directly…
- risk 0.28cvss 5.4epss 0.00
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype)…
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0.
- risk 0.28cvss 5.4epss 0.00
Code Injection in GitHub repository librenms/librenms prior to 23.9.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0.
- risk 0.27cvss 4.8epss 0.37
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "name" parameter when adding…
- risk 0.27cvss 5.3epss 0.01
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions the login method has no rate limit. An attacker may be able to leverage this vulnerability to gain…
- risk 0.26cvss —epss —
### Impact `POST /two-factor` had no rate limiting, lockout, or attempt counter. An attacker with valid credentials can submit unlimited TOTP guesses. The TOTP implementation accepts the current code plus one step on either side (`config/google2fa.php window=1`), so at any…
- risk 0.25cvss 4.6epss 0.31
librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameter: `ajax_form.php` -> param: state. Librenms versions up to 24.10.1 allow remote attackers to inject malicious scripts. When a user views or…
- risk 0.24cvss 4.8epss 0.00
LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against other users with access to the…
- risk 0.24cvss 4.8epss 0.00
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the port group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a port group, an HTTP…
- risk 0.24cvss 4.8epss 0.00
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the device group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a device group, an…
- risk 0.24cvss 4.8epss 0.00
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" tab of the Device page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when adding a service to…
Page 4 of 6