VYPR

Vendor CVEs

Librenms

All CVEs

122 total · sorted by risk
  • CVE-2024-50355MedNov 15, 2024
    risk 0.24cvss 4.8epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can edit the Display Name of a device, the application did not properly sanitize the user input in the device Display Name, if java script code is inside the name of the device…

  • CVE-2024-50351MedNov 15, 2024
    risk 0.24cvss 4.8epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "section" parameter of the "logs" tab of a device allows attackers to inject arbitrary JavaScript. This vulnerability results in the execution…

  • CVE-2024-50350MedNov 15, 2024
    risk 0.24cvss 4.8epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the "name" parameter when creating a new Port Group. This…

  • CVE-2024-49764MedNov 15, 2024
    risk 0.24cvss 4.8epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Capture Debug Information" page allows authenticated users to inject arbitrary JavaScript through the "hostname" parameter when creating a new…

  • CVE-2024-49759MedNov 15, 2024
    risk 0.24cvss 4.8epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Manage User Access" page allows authenticated users to inject arbitrary JavaScript through the "bill_name" parameter when creating a new bill.…

  • CVE-2024-49758MedNov 15, 2024
    risk 0.24cvss 4.8epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can add Notes to a device, the application did not properly sanitize the user input, when the ExamplePlugin enable, if java script code is inside the device's Notes, its will be…

  • CVE-2024-47528MedOct 1, 2024
    risk 0.24cvss 4.8epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be achieved by uploading a new Background for a Custom Map. Users with "admin" role can set background for a custom map, this allow the upload of SVG file that can…

  • CVE-2022-0772MedFeb 27, 2022
    risk 0.24cvss 4.8epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.2.2.

  • CVE-2025-23199MedJan 16, 2025
    risk 0.23cvss 4.6epss 0.01

    librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameter: `/ajax_form.php` -> param: descr. Librenms version up to 24.10.1 allow remote attackers to inject malicious scripts. When a user views or…

  • CVE-2025-23198MedJan 16, 2025
    risk 0.23cvss 4.6epss 0.00

    librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameters (Replace $DEVICE_ID with your specific $DEVICE_ID value):`/device/$DEVICE_ID/edit` -> param: display. Librenms versions up to 24.10.1 allow…

  • CVE-2024-56144MedJan 16, 2025
    risk 0.23cvss 4.6epss 0.00

    librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameters (Replace $DEVICE_ID with your specific $DEVICE_ID value):`/device/$DEVICE_ID/edit` -> param: display. Librenms versions up to 24.11.0 allow…

  • CVE-2026-26989MedFeb 20, 2026
    risk 0.21cvss 4.3epss 0.00

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are affected by a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Rules workflow. An attacker with administrative privileges can inject malicious scripts that…

  • CVE-2025-68614MedDec 23, 2025
    risk 0.21cvss 4.3epss 0.04

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule API is vulnerable to stored cross-site scripting. Alert rules can be created or updated via LibreNMS API. The alert rule name is not properly sanitized, and can…

  • CVE-2023-48294MedNov 17, 2023
    risk 0.21cvss 4.3epss 0.01

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions of LibreNMS when a user accesses their device dashboard, one request is sent to `graph.php` to access…

  • CVE-2025-62412LowOct 16, 2025
    risk 0.18cvss 3.8epss 0.00

    LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules page is not properly sanitized, and can be used to inject HTML code. This vulnerability is fixed in 25.10.0.

  • CVE-2025-65014LowNov 18, 2025
    risk 0.17cvss 3.7epss 0.00

    LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vulnerability was identified in the user management functionality of the LibreNMS application. This vulnerability allows administrators to create…

  • CVE-2024-47526LowOct 1, 2024
    risk 0.16cvss 3.5epss 0.00

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary JavaScript into the alert template's name. This script executes immediately upon…

  • CVE-2021-44278CriDec 3, 2021
    risk 0.00cvss 9.8epss 0.01

    Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.

  • CVE-2021-44279MedDec 1, 2021
    risk 0.00cvss 6.1epss 0.01

    Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php.

  • CVE-2021-44277MedDec 1, 2021
    risk 0.00cvss 6.1epss 0.01

    Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/common/alert-log.inc.php.

  • CVE-2021-31274MedSep 8, 2021
    risk 0.00cvss 5.4epss 0.01

    In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api->description variable. As a result, arbitrary Javascript code can get executed.

  • CVE-2018-18478MedOct 18, 2018
    risk 0.00cvss 6.1epss 0.02

    Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the dashboard_name parameter in the /ajax_form.php resource, related to html/includes/forms/add-dashboard.inc.php,…

Page 3 of 3