vciy

CVEs we hold for Librenms

Records whose assigning authority named Librenms as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-86427LibreNMS before 26.8.0 Argument Injection via graph_titlelibrenms
CVE-2026-86426LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusionlibrenms
CVE-2026-84194LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostnamelibrenms
CVE-2026-84193LibreNMS through 26.2.0 Stored Cross-Site Scripting via SNMPlibrenms
CVE-2026-84192LibreNMS before 26.3.1 Stored XSS via SNMP/Syslog Datalibrenms
CVE-2026-84191LibreNMS before 26.5.0 Stored XSS via SNMP VRF fieldslibrenms
CVE-2026-84190LibreNMS before 26.5.0 Remote Code Execution via AboutControllerlibrenms
CVE-2026-84189LibreNMS before 26.7.0 Stored XSS via Oxidized APIlibrenms
CVE-2026-84188librenms before 26.7.0 Stored XSS via graph_descr settingslibrenms
CVE-2026-80214LibreNMS Virtualisation Discovery Module RCElibrenms
CVE-2026-6204no title heldlibrenms
CVE-2026-55182LibreNMS: Remote Code Execution by Signal Alert Transportation Modulelibrenms
CVE-2026-45694LibreNMS: Reflected XSS in the Proxmox app view via unsanitized instance/vmid parameterslibrenms
CVE-2026-2728no title heldlibrenms
CVE-2026-27016LibreNMS has Stored XSS in Custom OID - unit parameter missing strip_tags()librenms
CVE-2026-26992LibreNMS has Stored Cross-Site Scripting via unsanitized /port-groups namelibrenms
CVE-2026-26991LibreNMS vulnerable to Stored Cross-site Scripting through unsanitized /device-groups namelibrenms
CVE-2026-26990LibreNMS has Time-Based Blind SQL Injection in address-search.inc.phplibrenms
CVE-2026-26989LibreNMS has Stored XSS in Alert Rulelibrenms
CVE-2026-26988LibreNMS: SQL Injection in ajax_table.php spreads through a covert data streamlibrenms
CVE-2026-26987LibreNMS affected by reflected XSS via email fieldlibrenms
CVE-2025-68614LibreNMS Alert Rule API Cross-Site Scripting Vulnerabilitylibrenms
CVE-2025-65093LibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.php endpointlibrenms
CVE-2025-65014LibreNMS has Weak Password Policylibrenms
CVE-2025-65013LibreNMS vulnerable to Reflected Cross-Site Scripting (XSS) in endpoint `/maps/nodeimage` parameter `Image Name`librenms
CVE-2025-62412LibreNMS alert-rules Cross-Site Scripting Vulnerabilitylibrenms
CVE-2025-62411Stored XSS in Alert Transport name field in LibreNMSlibrenms
CVE-2025-62365LibreNMS vulnerable to Reflected-XSS in `report_this` functionlibrenms
CVE-2025-55296LibreNMS allows stored XSS in Alert Template name fieldlibrenms
CVE-2025-54138LibreNMS has Authenticated Local File Inclusion in ajax_form.php that Allows RCElibrenms
CVE-2025-47931LibreNMS stored Cross-site Scripting vulnerability in poller group namelibrenms
CVE-2025-23201Reflected Cross-site Scripting on error alert in librenmslibrenms
CVE-2025-23200Stored XSS-LibreNMS-Misc Section in librenmslibrenms
CVE-2025-23199Stored XSS-LibreNMS-Ports in librenmslibrenms
CVE-2025-23198Stored-XSS-LibreNMS-Display-Name in librenmslibrenms
CVE-2024-56144Stored XSS-LibreNMS-Display Name 2 in librenmslibrenms
CVE-2024-52526LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/services.inc.phplibrenms
CVE-2024-51497LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/print-customoid.phplibrenms
CVE-2024-51496LibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/html/pages/wireless.inc.phplibrenms
CVE-2024-51495LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/dev-overview-data.inc.phplibrenms
CVE-2024-51494LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.phplibrenms
CVE-2024-50355LibreNMS has a Persistent XSS from Insecure Input Sanitization Affects Multiple Endpointslibrenms
CVE-2024-50352LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/overview/services.inc.phplibrenms
CVE-2024-50351LibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/functions.phplibrenms
CVE-2024-50350LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.phplibrenms
CVE-2024-49764LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/capture.inc.phplibrenms
CVE-2024-49759LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/edituser.inc.phplibrenms
CVE-2024-49758LibreNMS has a stored XSS in ExamplePlugin with Device's Noteslibrenms
CVE-2024-49754LibreNMS has a stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/api-access.inc.phplibrenms
CVE-2024-47528LibreNMS Contains a Stored XSS via File Uploadlibrenms
CVE-2024-47527LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device-dependencies.inc.phplibrenms
CVE-2024-47526LibreNMS has a Self-XSS ('Cross-site Scripting') in librenms/includes/html/modal/alert_template.inc.phplibrenms
CVE-2024-47525Stored XSS ('Cross-site Scripting') in librenms/includes/html/print-alert-rules.phplibrenms
CVE-2024-47524LibreNMS has Stored Cross-site Scripting vulnerability in "Device Group" Namelibrenms
CVE-2024-47523LibreNMS has Stored Cross-site Scripting vulnerability in "Alert Transports" featurelibrenms
CVE-2024-32480LibreNMS's Time-Based Blind SQL injection leads to database extractionlibrenms
CVE-2024-32479LibreNMS's Improper Sanitization on Service template name leads to Stored XSSlibrenms
CVE-2024-32461LibreNMS vulnerable to time-based SQL injection that leads to database extractionlibrenms
CVE-2023-5591SQL Injection in librenms/librenmslibrenms/librenms
CVE-2023-5060Cross-site Scripting (XSS) - DOM in librenms/librenmslibrenms/librenms
CVE-2023-4982Cross-site Scripting (XSS) - Stored in librenms/librenmslibrenms/librenms
CVE-2023-4981Cross-site Scripting (XSS) - DOM in librenms/librenmslibrenms/librenms
CVE-2023-4980Cross-site Scripting (XSS) - Generic in librenms/librenmslibrenms/librenms
CVE-2023-4979Cross-site Scripting (XSS) - Reflected in librenms/librenmslibrenms/librenms
CVE-2023-4978Cross-site Scripting (XSS) - DOM in librenms/librenmslibrenms/librenms
CVE-2023-4977Code Injection in librenms/librenmslibrenms/librenms
CVE-2023-48295Cross-site Scripting at Device groups Deletion feature in LibreNMSlibrenms
CVE-2023-48294Broken Access control on Graphs Feature in LibreNMSlibrenms
CVE-2023-46745Rate limiting Bypass on login page in libreNMSlibrenms
CVE-2023-4347Cross-site Scripting (XSS) - Reflected in librenms/librenmslibrenms/librenms
CVE-2022-4070Insufficient Session Expiration in librenms/librenmslibrenms/librenms
CVE-2022-4069Cross-site Scripting (XSS) - Generic in librenms/librenmslibrenms/librenms
CVE-2022-4068Improperly Controlled Modification of Dynamically-Determined Object Attributes in librenms/librenmslibrenms/librenms
CVE-2022-4067Cross-site Scripting (XSS) - Stored in librenms/librenmslibrenms/librenms
CVE-2022-3562Cross-site Scripting (XSS) - Stored in librenms/librenmslibrenms/librenms
CVE-2022-3561Cross-site Scripting (XSS) - Generic in librenms/librenmslibrenms/librenms
CVE-2022-3525Deserialization of Untrusted Data in librenms/librenmslibrenms/librenms
CVE-2022-3516Cross-site Scripting (XSS) - Stored in librenms/librenmslibrenms/librenms
CVE-2022-3231Cross-site Scripting (XSS) - Stored in librenms/librenmslibrenms/librenms
CVE-2022-0772Cross-site Scripting (XSS) - Stored in librenms/librenmslibrenms/librenms
CVE-2022-0589Cross-site Scripting (XSS) - Stored in librenms/librenmslibrenms/librenms
CVE-2022-0588Missing Authorization in librenms/librenmslibrenms/librenms
CVE-2022-0587Improper Authorization in librenms/librenmslibrenms/librenms
CVE-2022-0580Incorrect Authorization in librenms/librenmslibrenms/librenms
CVE-2022-0576Cross-site Scripting (XSS) - Generic in librenms/librenmslibrenms/librenms
CVE-2022-0575Cross-site Scripting (XSS) - Stored in librenms/librenmslibrenms/librenms
CVE-2020-36947LibreNMS 1.46 - MAC Accounting Graph Authenticated SQL InjectionLibreNMS
CVE-2020-15875no title heldLibreNMS

88 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.