VYPR

Librenms

by Librenms

Source repositories

CVEs (107)

  • CVE-2024-47526LowOct 1, 2024
    risk 0.16cvss 3.5epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary JavaScript into the alert template's name. This script executes immediately upon…

  • CVE-2026-45694Aug 12, 2026
    risk 0.00cvss epss

    ### Summary `LegacyController.php:75` writes the page title into a `document.title` JS assignment using string interpolation. `apps/proxmox.inc.php` pushes `$vars['instance']` and `$vars['vmid']` (GET params, only `strip_tags()` applied) directly into `$pagetitle`. A single…

  • CVE-2021-44278CriDec 3, 2021
    risk 0.00cvss 9.8epss 0.01

    Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.

  • CVE-2021-44279MedDec 1, 2021
    risk 0.00cvss 6.1epss 0.01

    Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php.

  • CVE-2021-44277MedDec 1, 2021
    risk 0.00cvss 6.1epss 0.01

    Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/common/alert-log.inc.php.

  • CVE-2021-31274MedSep 8, 2021
    risk 0.00cvss 5.4epss 0.01

    In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api->description variable. As a result, arbitrary Javascript code can get executed.

  • CVE-2018-18478MedOct 18, 2018
    risk 0.00cvss 6.1epss 0.02

    Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the dashboard_name parameter in the /ajax_form.php resource, related to html/includes/forms/add-dashboard.inc.php,…

Page 6 of 6