VYPR

Vendor CVEs

Librenms

All CVEs

122 total · sorted by risk
  • CVE-2019-10667MedSep 9, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and disclose local file paths.

  • CVE-2019-15230MedAug 28, 2019
    risk 0.35cvss 5.4epss 0.01

    LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an…

  • CVE-2025-47931MedMay 17, 2025
    risk 0.34cvss 6.1epss 0.12

    LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scripting (XSS) Vulnerability in the `group name` parameter of the `http://localhost/poller/groups` form. This vulnerability allows attackers to inject…

  • CVE-2023-48295MedNov 17, 2023
    risk 0.34cvss 6.3epss 0.01

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. Affected versions are subject to a cross site scripting (XSS) vulnerability in the device group popups. This issue has been…

  • CVE-2023-4347MedAug 15, 2023
    risk 0.34cvss 5.4epss 0.70

    Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0.

  • CVE-2026-84191MedSep 1, 2026
    risk 0.33cvss 6.1epss 0.00

    LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered without sanitization. Attackers controlling a monitored network device…

  • CVE-2026-26987MedFeb 20, 2026
    risk 0.33cvss 6.1epss 0.00

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to Reflected XSS attacks via email field. This issue has been fixed in version 26.2.0.

  • CVE-2025-65013MedNov 18, 2025
    risk 0.33cvss 6.2epss 0.00

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scripting (XSS) vulnerability was identified in the LibreNMS application at the /maps/nodeimage endpoint. The Image Name parameter is reflected in the…

  • CVE-2025-62365MedOct 13, 2025
    risk 0.33cvss 6.1epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in `report_this` function in `librenms/includes/functions.php`. The `report_this` function had improper filtering (`htmlentities` function was incorrectly use in…

  • CVE-2023-5060MedSep 19, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.

  • CVE-2023-4978MedSep 15, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.

  • CVE-2022-3561MedNov 20, 2022
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.

  • CVE-2022-3516MedNov 20, 2022
    risk 0.33cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.

  • CVE-2022-36746MedAug 30, 2022
    risk 0.33cvss 6.1epss 0.01

    LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php.

  • CVE-2022-36745MedAug 30, 2022
    risk 0.33cvss 6.1epss 0.01

    LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php.

  • CVE-2022-29711MedJun 2, 2022
    risk 0.33cvss 6.1epss 0.01

    LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogController.php.

  • CVE-2022-0576MedFeb 14, 2022
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0.

  • CVE-2021-43324MedNov 3, 2021
    risk 0.33cvss 6.1epss 0.01

    LibreNMS through 21.10.2 allows XSS via a widget title.

  • CVE-2024-53457MedDec 5, 2024
    risk 0.32cvss 5.4epss 0.45

    A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.

  • CVE-2022-4069MedNov 20, 2022
    risk 0.32cvss 4.8epss 0.93

    Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.

  • CVE-2017-16759MedNov 9, 2017
    risk 0.32cvss 5.9epss 0.02

    The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.

  • CVE-2026-84193MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or…

  • CVE-2026-49870MedAug 19, 2026
    risk 0.31cvss 5.9epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or attempt counter, allowing an attacker with valid credentials to submit unlimited TOTP guesses against the three accepted codes created by config/google2fa.php…

  • CVE-2022-4068MedNov 20, 2022
    risk 0.31cvss 5.4epss 0.36

    A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attack that enables an attacker with a low privilege user to…

  • CVE-2025-62411MedOct 16, 2025
    risk 0.30cvss 5.5epss 0.13

    LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When an administrator creates a new Alert Transport, the value of the Transport…

  • CVE-2025-55296MedAug 18, 2025
    risk 0.30cvss 5.5epss 0.12

    librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. This allows a user with the admin role to inject malicious JavaScript, which will be…

  • CVE-2025-65093MedNov 18, 2025
    risk 0.29cvss 5.5epss 0.04

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application at the /ajax_output.php endpoint. The hostname parameter is interpolated directly…

  • CVE-2026-45694MedAug 26, 2026
    risk 0.28cvss 5.4epss 0.00

    LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected into the page title without adequate…

  • CVE-2026-27016MedFeb 20, 2026
    risk 0.28cvss 5.4epss 0.00

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype)…

  • CVE-2023-4982MedSep 15, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0.

  • CVE-2023-4981MedSep 15, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.

  • CVE-2023-4980MedSep 15, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0.

  • CVE-2023-4979MedSep 15, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0.

  • CVE-2023-4977MedSep 15, 2023
    risk 0.28cvss 5.4epss 0.01

    Code Injection in GitHub repository librenms/librenms prior to 23.9.0.

  • CVE-2022-3231MedSep 17, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0.

  • CVE-2022-0589MedFeb 15, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0.

  • CVE-2022-0575MedFeb 14, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0.

  • CVE-2024-50352MedNov 15, 2024
    risk 0.27cvss 4.8epss 0.38

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "name" parameter when adding…

  • CVE-2023-46745MedNov 17, 2023
    risk 0.27cvss 5.3epss 0.01

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions the login method has no rate limit. An attacker may be able to leverage this vulnerability to gain…

  • CVE-2020-15875MedSep 13, 2026
    risk 0.26cvss 5.0epss 0.00

    An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endpoint. This affects as-selection.inc.php,…

  • CVE-2025-23200MedJan 16, 2025
    risk 0.25cvss 4.6epss 0.31

    librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameter: `ajax_form.php` -> param: state. Librenms versions up to 24.10.1 allow remote attackers to inject malicious scripts. When a user views or…

  • CVE-2026-84188MedSep 1, 2026
    risk 0.24cvss 4.8epss 0.00

    LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr. configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrator can store a malicious HTML payload that…

  • CVE-2026-2728MedApr 13, 2026
    risk 0.24cvss 4.8epss 0.00

    LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against other users with access to the…

  • CVE-2026-26992MedFeb 20, 2026
    risk 0.24cvss 4.8epss 0.00

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the port group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a port group, an HTTP…

  • CVE-2026-26991MedFeb 20, 2026
    risk 0.24cvss 4.8epss 0.00

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the device group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a device group, an…

  • CVE-2024-52526MedNov 15, 2024
    risk 0.24cvss 4.8epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" tab of the Device page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when adding a service to…

  • CVE-2024-51497MedNov 15, 2024
    risk 0.24cvss 4.8epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Custom OID" tab of a device allows authenticated users to inject arbitrary JavaScript through the "unit" parameter when creating a new OID. This…

  • CVE-2024-51496MedNov 15, 2024
    risk 0.24cvss 4.8epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "metric" parameter of the "/wireless" and "/health" endpoints allows attackers to inject arbitrary JavaScript. This vulnerability results in…

  • CVE-2024-51495MedNov 15, 2024
    risk 0.24cvss 4.8epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "overwrite_ip" parameter when editing a device. This…

  • CVE-2024-51494MedNov 15, 2024
    risk 0.24cvss 4.8epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when editing a device's port…