📦 Librenms

by Librenms

🔍 What is Librenms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-26988

CRITICAL CVSS 9.1 Feb 20, 2026

This SQL injection vulnerability in LibreNMS allows attackers to execute arbitrary SQL commands through the ajax_table.php endpoint when searching IPv6 addresses. Attackers could potentially access, m...

CVE-2022-29712

CRITICAL CVSS 9.8 Jun 2, 2022

CVE-2022-29712 allows remote attackers to execute arbitrary commands on LibreNMS servers through command injection vulnerabilities in service_ip, hostname, and service_param parameters. This affects a...

CVE-2026-26990

HIGH CVSS 8.8 Feb 20, 2026

LibreNMS versions 25.12.0 and below contain a time-based blind SQL injection vulnerability in the address-search functionality. Authenticated attackers can exploit this to infer database information b...

CVE-2025-54138

HIGH CVSS 7.5 Jul 22, 2025

This vulnerability in LibreNMS allows remote file inclusion via the ajax_form.php endpoint, potentially leading to remote code execution. Attackers can exploit this by controlling POST input to includ...

CVE-2024-47524

HIGH CVSS 7.2 Oct 1, 2024

This is a stored cross-site scripting (XSS) vulnerability in LibreNMS where administrators can inject malicious JavaScript into Device Group names. When other users view these groups, the JavaScript e...

CVE-2024-47527

HIGH CVSS 7.5 Oct 1, 2024

This stored XSS vulnerability in LibreNMS allows authenticated users to inject malicious JavaScript through device names in the Device Dependencies feature. When other users view affected pages, the m...

CVE-2024-32480

HIGH CVSS 7.2 Apr 22, 2024

This SQL injection vulnerability in LibreNMS allows attackers to manipulate database queries through the 'order' parameter, potentially extracting entire database contents. All LibreNMS instances runn...

CVE-2024-32461

HIGH CVSS 7.1 Apr 22, 2024

This SQL injection vulnerability in LibreNMS allows authenticated users with global read privileges to execute arbitrary SQL commands via the package parameter in the search endpoint. Attackers can ex...

CVE-2022-0580

HIGH CVSS 7.1 Feb 14, 2022

CVE-2022-0580 is an incorrect authorization vulnerability in LibreNMS that allows authenticated users to access unauthorized functionality. This affects LibreNMS installations prior to version 22.2.0 ...

CVE-2026-26991

MEDIUM CVSS 4.8 Feb 20, 2026

This stored XSS vulnerability in LibreNMS allows attackers with admin privileges to inject malicious scripts into device group names, which execute when other users view those groups. It affects Libre...

CVE-2026-26989

MEDIUM CVSS 4.3 Feb 20, 2026

This is a stored cross-site scripting (XSS) vulnerability in LibreNMS that allows attackers with administrative privileges to inject malicious scripts into the Alert Rules workflow. When other users v...

CVE-2025-68614

MEDIUM CVSS 4.3 Dec 23, 2025

This stored XSS vulnerability in LibreNMS allows attackers to inject malicious HTML/JavaScript into alert rule names via the API. When administrators view these alert rules, the malicious code execute...

CVE-2025-65093

MEDIUM CVSS 5.5 Nov 18, 2025

CVE-2025-65093 is a boolean-based blind SQL injection vulnerability in LibreNMS's /ajax_output.php endpoint. Attackers can manipulate the hostname parameter to infer database contents through conditio...

CVE-2025-65013

MEDIUM CVSS 6.2 Nov 18, 2025

This reflected cross-site scripting (XSS) vulnerability in LibreNMS allows attackers to craft malicious URLs that execute arbitrary JavaScript in victims' browsers when visited. The vulnerability affe...

CVE-2025-47931

MEDIUM CVSS 6.1 May 17, 2025

This stored XSS vulnerability in LibreNMS allows attackers to inject malicious scripts into the 'group name' parameter of the poller groups form. When other users view the affected page, the scripts e...

CVE-2025-23198

MEDIUM CVSS 4.6 Jan 16, 2025

This stored XSS vulnerability in LibreNMS allows attackers to inject malicious scripts into device display parameters. When administrators view or edit affected devices, the scripts execute in their b...

CVE-2025-23200

MEDIUM CVSS 4.6 Jan 16, 2025

This stored cross-site scripting (XSS) vulnerability in LibreNMS allows attackers to inject malicious scripts through the state parameter in ajax_form.php. When users view pages containing the injecte...

CVE-2024-53457

MEDIUM CVSS 5.4 Dec 5, 2024

A stored cross-site scripting (XSS) vulnerability in LibreNMS allows attackers to inject malicious scripts into the Display Name parameter in Device Settings. When other users view affected device pag...

CVE-2024-52526

MEDIUM CVSS 4.8 Nov 15, 2024

This stored XSS vulnerability in LibreNMS allows authenticated users to inject malicious JavaScript into the Services tab description field. When other users view the compromised device page, the scri...

CVE-2024-51494

MEDIUM CVSS 4.8 Nov 15, 2024

This stored XSS vulnerability in LibreNMS allows authenticated users to inject malicious JavaScript into the Port Settings page via the 'descr' parameter. When other users view the compromised port se...

CVE-2024-51496

MEDIUM CVSS 4.8 Nov 15, 2024

This is a reflected cross-site scripting (XSS) vulnerability in LibreNMS that allows attackers to inject malicious JavaScript via the 'metric' parameter in wireless and health endpoints. When exploite...

CVE-2024-50355

MEDIUM CVSS 4.8 Nov 15, 2024

This is a stored cross-site scripting (XSS) vulnerability in LibreNMS where administrators can inject malicious JavaScript into device display names. When other users view devices with these names, th...

CVE-2024-49764

MEDIUM CVSS 4.8 Nov 15, 2024

This stored XSS vulnerability in LibreNMS allows authenticated users to inject malicious JavaScript through the device hostname parameter. When victims view the Capture Debug Information page, their s...

CVE-2024-50351

MEDIUM CVSS 4.8 Nov 15, 2024

A reflected Cross-Site Scripting (XSS) vulnerability in LibreNMS allows attackers to inject malicious JavaScript via the 'section' parameter in device logs. When users access pages with crafted parame...

CVE-2024-49758

MEDIUM CVSS 4.8 Nov 15, 2024

This is a stored cross-site scripting (XSS) vulnerability in LibreNMS where administrators can inject malicious JavaScript into device notes. When the ExamplePlugin is enabled, this JavaScript execute...

CVE-2025-65014

LOW CVSS 3.7 Nov 18, 2025

A weak password policy vulnerability in LibreNMS allows administrators to create user accounts with extremely weak passwords like '12345678'. This exposes the platform to brute-force and credential st...