Vendor CVEs
Librenms
All CVEs
122 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-10667 | Med | 0.35 | 5.3 | 0.01 | Sep 9, 2019 | An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and disclose local file paths. | ||
| CVE-2019-15230 | Med | 0.35 | 5.4 | 0.01 | Aug 28, 2019 | LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an… | ||
| CVE-2025-47931 | Med | 0.34 | 6.1 | 0.12 | May 17, 2025 | LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scripting (XSS) Vulnerability in the `group name` parameter of the `http://localhost/poller/groups` form. This vulnerability allows attackers to inject… | ||
| CVE-2023-48295 | Med | 0.34 | 6.3 | 0.01 | Nov 17, 2023 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. Affected versions are subject to a cross site scripting (XSS) vulnerability in the device group popups. This issue has been… | ||
| CVE-2023-4347 | Med | 0.34 | 5.4 | 0.70 | Aug 15, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0. | ||
| CVE-2026-84191 | Med | 0.33 | 6.1 | 0.00 | Sep 1, 2026 | LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered without sanitization. Attackers controlling a monitored network device… | ||
| CVE-2026-26987 | Med | 0.33 | 6.1 | 0.00 | Feb 20, 2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to Reflected XSS attacks via email field. This issue has been fixed in version 26.2.0. | ||
| CVE-2025-65013 | Med | 0.33 | 6.2 | 0.00 | Nov 18, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scripting (XSS) vulnerability was identified in the LibreNMS application at the /maps/nodeimage endpoint. The Image Name parameter is reflected in the… | ||
| CVE-2025-62365 | Med | 0.33 | 6.1 | 0.00 | Oct 13, 2025 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in `report_this` function in `librenms/includes/functions.php`. The `report_this` function had improper filtering (`htmlentities` function was incorrectly use in… | ||
| CVE-2023-5060 | Med | 0.33 | 6.1 | 0.01 | Sep 19, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1. | ||
| CVE-2023-4978 | Med | 0.33 | 6.1 | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0. | ||
| CVE-2022-3561 | Med | 0.33 | 6.1 | 0.01 | Nov 20, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0. | ||
| CVE-2022-3516 | Med | 0.33 | 6.1 | 0.00 | Nov 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. | ||
| CVE-2022-36746 | Med | 0.33 | 6.1 | 0.01 | Aug 30, 2022 | LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php. | ||
| CVE-2022-36745 | Med | 0.33 | 6.1 | 0.01 | Aug 30, 2022 | LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php. | ||
| CVE-2022-29711 | Med | 0.33 | 6.1 | 0.01 | Jun 2, 2022 | LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogController.php. | ||
| CVE-2022-0576 | Med | 0.33 | 6.1 | 0.01 | Feb 14, 2022 | Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0. | ||
| CVE-2021-43324 | Med | 0.33 | 6.1 | 0.01 | Nov 3, 2021 | LibreNMS through 21.10.2 allows XSS via a widget title. | ||
| CVE-2024-53457 | Med | 0.32 | 5.4 | 0.45 | Dec 5, 2024 | A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter. | ||
| CVE-2022-4069 | Med | 0.32 | 4.8 | 0.93 | Nov 20, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0. | ||
| CVE-2017-16759 | Med | 0.32 | 5.9 | 0.02 | Nov 9, 2017 | The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php. | ||
| CVE-2026-84193 | Med | 0.31 | — | 0.00 | Sep 1, 2026 | LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or… | ||
| CVE-2026-49870 | Med | 0.31 | 5.9 | 0.00 | Aug 19, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or attempt counter, allowing an attacker with valid credentials to submit unlimited TOTP guesses against the three accepted codes created by config/google2fa.php… | ||
| CVE-2022-4068 | Med | 0.31 | 5.4 | 0.36 | Nov 20, 2022 | A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attack that enables an attacker with a low privilege user to… | ||
| CVE-2025-62411 | Med | 0.30 | 5.5 | 0.13 | Oct 16, 2025 | LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When an administrator creates a new Alert Transport, the value of the Transport… | ||
| CVE-2025-55296 | Med | 0.30 | 5.5 | 0.12 | Aug 18, 2025 | librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. This allows a user with the admin role to inject malicious JavaScript, which will be… | ||
| CVE-2025-65093 | Med | 0.29 | 5.5 | 0.04 | Nov 18, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application at the /ajax_output.php endpoint. The hostname parameter is interpolated directly… | ||
| CVE-2026-45694 | Med | 0.28 | 5.4 | 0.00 | Aug 26, 2026 | LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected into the page title without adequate… | ||
| CVE-2026-27016 | Med | 0.28 | 5.4 | 0.00 | Feb 20, 2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype)… | ||
| CVE-2023-4982 | Med | 0.28 | 5.4 | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0. | ||
| CVE-2023-4981 | Med | 0.28 | 5.4 | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0. | ||
| CVE-2023-4980 | Med | 0.28 | 5.4 | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0. | ||
| CVE-2023-4979 | Med | 0.28 | 5.4 | 0.01 | Sep 15, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0. | ||
| CVE-2023-4977 | Med | 0.28 | 5.4 | 0.01 | Sep 15, 2023 | Code Injection in GitHub repository librenms/librenms prior to 23.9.0. | ||
| CVE-2022-3231 | Med | 0.28 | 5.4 | 0.01 | Sep 17, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0. | ||
| CVE-2022-0589 | Med | 0.28 | 5.4 | 0.01 | Feb 15, 2022 | Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0. | ||
| CVE-2022-0575 | Med | 0.28 | 5.4 | 0.01 | Feb 14, 2022 | Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0. | ||
| CVE-2024-50352 | Med | 0.27 | 4.8 | 0.38 | Nov 15, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "name" parameter when adding… | ||
| CVE-2023-46745 | Med | 0.27 | 5.3 | 0.01 | Nov 17, 2023 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions the login method has no rate limit. An attacker may be able to leverage this vulnerability to gain… | ||
| CVE-2020-15875 | Med | 0.26 | 5.0 | 0.00 | Sep 13, 2026 | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endpoint. This affects as-selection.inc.php,… | ||
| CVE-2025-23200 | Med | 0.25 | 4.6 | 0.31 | Jan 16, 2025 | librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameter: `ajax_form.php` -> param: state. Librenms versions up to 24.10.1 allow remote attackers to inject malicious scripts. When a user views or… | ||
| CVE-2026-84188 | Med | 0.24 | 4.8 | 0.00 | Sep 1, 2026 | LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr. configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrator can store a malicious HTML payload that… | ||
| CVE-2026-2728 | Med | 0.24 | 4.8 | 0.00 | Apr 13, 2026 | LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against other users with access to the… | ||
| CVE-2026-26992 | Med | 0.24 | 4.8 | 0.00 | Feb 20, 2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the port group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a port group, an HTTP… | ||
| CVE-2026-26991 | Med | 0.24 | 4.8 | 0.00 | Feb 20, 2026 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the device group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a device group, an… | ||
| CVE-2024-52526 | Med | 0.24 | 4.8 | 0.00 | Nov 15, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" tab of the Device page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when adding a service to… | ||
| CVE-2024-51497 | Med | 0.24 | 4.8 | 0.00 | Nov 15, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Custom OID" tab of a device allows authenticated users to inject arbitrary JavaScript through the "unit" parameter when creating a new OID. This… | ||
| CVE-2024-51496 | Med | 0.24 | 4.8 | 0.00 | Nov 15, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "metric" parameter of the "/wireless" and "/health" endpoints allows attackers to inject arbitrary JavaScript. This vulnerability results in… | ||
| CVE-2024-51495 | Med | 0.24 | 4.8 | 0.00 | Nov 15, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "overwrite_ip" parameter when editing a device. This… | ||
| CVE-2024-51494 | Med | 0.24 | 4.8 | 0.00 | Nov 15, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when editing a device's port… |
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and disclose local file paths.
- risk 0.35cvss 5.4epss 0.01
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an…
- risk 0.34cvss 6.1epss 0.12
LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scripting (XSS) Vulnerability in the `group name` parameter of the `http://localhost/poller/groups` form. This vulnerability allows attackers to inject…
- risk 0.34cvss 6.3epss 0.01
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. Affected versions are subject to a cross site scripting (XSS) vulnerability in the device group popups. This issue has been…
- risk 0.34cvss 5.4epss 0.70
Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0.
- risk 0.33cvss 6.1epss 0.00
LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered without sanitization. Attackers controlling a monitored network device…
- risk 0.33cvss 6.1epss 0.00
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to Reflected XSS attacks via email field. This issue has been fixed in version 26.2.0.
- risk 0.33cvss 6.2epss 0.00
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scripting (XSS) vulnerability was identified in the LibreNMS application at the /maps/nodeimage endpoint. The Image Name parameter is reflected in the…
- risk 0.33cvss 6.1epss 0.00
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in `report_this` function in `librenms/includes/functions.php`. The `report_this` function had improper filtering (`htmlentities` function was incorrectly use in…
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.
- risk 0.33cvss 6.1epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
- risk 0.33cvss 6.1epss 0.01
LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php.
- risk 0.33cvss 6.1epss 0.01
LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php.
- risk 0.33cvss 6.1epss 0.01
LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogController.php.
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0.
- risk 0.33cvss 6.1epss 0.01
LibreNMS through 21.10.2 allows XSS via a widget title.
- risk 0.32cvss 5.4epss 0.45
A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.
- risk 0.32cvss 4.8epss 0.93
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.
- risk 0.32cvss 5.9epss 0.02
The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.
- risk 0.31cvss —epss 0.00
LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or…
- risk 0.31cvss 5.9epss 0.00
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or attempt counter, allowing an attacker with valid credentials to submit unlimited TOTP guesses against the three accepted codes created by config/google2fa.php…
- risk 0.31cvss 5.4epss 0.36
A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attack that enables an attacker with a low privilege user to…
- risk 0.30cvss 5.5epss 0.13
LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When an administrator creates a new Alert Transport, the value of the Transport…
- risk 0.30cvss 5.5epss 0.12
librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. This allows a user with the admin role to inject malicious JavaScript, which will be…
- risk 0.29cvss 5.5epss 0.04
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application at the /ajax_output.php endpoint. The hostname parameter is interpolated directly…
- risk 0.28cvss 5.4epss 0.00
LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected into the page title without adequate…
- risk 0.28cvss 5.4epss 0.00
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype)…
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0.
- risk 0.28cvss 5.4epss 0.01
Code Injection in GitHub repository librenms/librenms prior to 23.9.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0.
- risk 0.27cvss 4.8epss 0.38
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "name" parameter when adding…
- risk 0.27cvss 5.3epss 0.01
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions the login method has no rate limit. An attacker may be able to leverage this vulnerability to gain…
- risk 0.26cvss 5.0epss 0.00
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endpoint. This affects as-selection.inc.php,…
- risk 0.25cvss 4.6epss 0.31
librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameter: `ajax_form.php` -> param: state. Librenms versions up to 24.10.1 allow remote attackers to inject malicious scripts. When a user views or…
- risk 0.24cvss 4.8epss 0.00
LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr. configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrator can store a malicious HTML payload that…
- risk 0.24cvss 4.8epss 0.00
LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against other users with access to the…
- risk 0.24cvss 4.8epss 0.00
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the port group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a port group, an HTTP…
- risk 0.24cvss 4.8epss 0.00
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the device group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a device group, an…
- risk 0.24cvss 4.8epss 0.00
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" tab of the Device page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when adding a service to…
- risk 0.24cvss 4.8epss 0.00
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Custom OID" tab of a device allows authenticated users to inject arbitrary JavaScript through the "unit" parameter when creating a new OID. This…
- risk 0.24cvss 4.8epss 0.00
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "metric" parameter of the "/wireless" and "/health" endpoints allows attackers to inject arbitrary JavaScript. This vulnerability results in…
- risk 0.24cvss 4.8epss 0.00
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "overwrite_ip" parameter when editing a device. This…
- risk 0.24cvss 4.8epss 0.00
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when editing a device's port…
Page 2 of 3