Home/Product/librenms
Product

librenms

104 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-51092
< 24.10.0
LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php'
9.1CRITICAL
CVE-2026-6204
< 26.3.0
LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locati
7.2HIGH
CVE-2026-2728
< 26.3.0
LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Succes
4.8MEDIUM
CVE-2026-26992
< 26.2.0
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the port group name is
4.8MEDIUM
CVE-2026-26991
< 26.2.0
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the device group name
4.8MEDIUM
CVE-2026-27016
>= 24.10.0 and < 26.2.0
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to St
5.4MEDIUM
CVE-2026-26990
< 26.2.0
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below have a Time-Based Blind S
8.8HIGH
CVE-2026-26989
< 26.2.0
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are affected by a Stored
4.3MEDIUM
CVE-2026-26988
< 26.2.0
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection
9.1CRITICAL
CVE-2026-26987
< 26.2.0
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to Reflec
6.1MEDIUM
CVE-2020-36947
all versions
LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attack
7.1HIGH
CVE-2025-68614
< 25.12.0
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule API is vuln
4.3MEDIUM
CVE-2025-65093
< 25.11.0
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL
5.5MEDIUM
CVE-2025-65014
< 25.11.0
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vul
3.7LOW
CVE-2025-65013
< 25.11.0
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scr
6.2MEDIUM
CVE-2025-62412
>= 25.8.0 and < 25.10.0
LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules page is not
3.8LOW
CVE-2025-62411
< 25.10.0
LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (
5.5MEDIUM
CVE-2025-62365
< 25.7.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in `report_t
6.1MEDIUM
CVE-2025-55296
< 25.8.0
librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in
5.5MEDIUM
CVE-2025-54138
< 25.7.0
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardwar
7.5HIGH
CVE-2025-47931
< 25.5.0
LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scriptin
6.1MEDIUM
CVE-2025-23201
< 24.11.0
librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to Cross-site Scripting (XSS)
5.4MEDIUM
CVE-2025-23200
< 24.11.0
librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the paramet
4.6MEDIUM
CVE-2025-23199
< 24.11.0
librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the paramet
4.6MEDIUM
CVE-2025-23198
< 24.11.0
librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the paramet
4.6MEDIUM
CVE-2024-56144
< 24.12.0
librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the paramet
4.6MEDIUM
CVE-2024-53457
>= 24.9.0 and <= 24.10.0
A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers
5.4MEDIUM
CVE-2024-52526
all versions
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in t
4.8MEDIUM
CVE-2024-51497
< 24.10.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in t
4.8MEDIUM
CVE-2024-51496
< 24.10.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability i
4.8MEDIUM
CVE-2024-51495
< 24.10.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in t
4.8MEDIUM
CVE-2024-51494
< 24.10.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in t
4.8MEDIUM
CVE-2024-50355
< 24.10.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can edit the Display Name of a de
4.8MEDIUM
CVE-2024-50352
< 24.10.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in t
4.8MEDIUM
CVE-2024-50351
< 24.10.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability i
4.8MEDIUM
CVE-2024-50350
< 24.10.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in t
4.8MEDIUM
CVE-2024-49764
< 24.10.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in t
4.8MEDIUM
CVE-2024-49759
< 24.10.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in t
4.8MEDIUM
CVE-2024-49758
< 24.10.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can add Notes to a device, the ap
4.8MEDIUM
CVE-2024-49754
< 24.10.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in t
7.5HIGH
CVE-2024-47528
< 24.9.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be achieved by u
4.8MEDIUM
CVE-2024-47527
< 24.9.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in t
7.5HIGH
CVE-2024-47526
< 24.9.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability i
3.5LOW
CVE-2024-47525
< 24.9.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in t
7.5HIGH
CVE-2024-47524
< 24.9.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can create a Device Groups, the a
7.2HIGH
CVE-2024-47523
< 24.9.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in t
7.5HIGH
CVE-2024-32480
< 24.4.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Versions prior to 24.4.0 are vulnerable to SQL injecti
7.2HIGH
CVE-2024-32479
< 24.4.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to version 24.4.0, there is improper sanitizatio
7.1HIGH
CVE-2024-32461
< 24.4.0
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A SQL injection vulnerability in POST /search/search=p
7.1HIGH
CVE-2023-48294
< 23.11.0
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardwar
4.3MEDIUM
CVE-2023-46745
< 23.11.0
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardwar
5.3MEDIUM
CVE-2023-48295
< 23.11.0
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardwar
6.3MEDIUM
CVE-2023-5591
<= 23.9.1
SQL Injection in GitHub repository librenms/librenms prior to 23.10.0.
6.5MEDIUM
CVE-2023-5060
< 23.9.1
Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.
6.1MEDIUM
CVE-2023-4982
< 23.9.0
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0.
5.4MEDIUM
CVE-2023-4981
< 23.9.0
Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.
5.4MEDIUM
CVE-2023-4980
< 23.9.0
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0.
5.4MEDIUM
CVE-2023-4979
< 23.9.0
Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0.
5.4MEDIUM
CVE-2023-4978
< 23.9.0
Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.
6.1MEDIUM
CVE-2023-4977
< 23.9.0
Code Injection in GitHub repository librenms/librenms prior to 23.9.0.
5.4MEDIUM
CVE-2023-4347
< 23.8.0
Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0.
5.4MEDIUM
CVE-2022-4070
< 22.10.0
Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.
9.8CRITICAL
CVE-2022-4069
< 22.10.0
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.
4.8MEDIUM
CVE-2022-4068
< 22.10.0
A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, th
5.4MEDIUM
CVE-2022-4067
< 22.10.0
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
5.4MEDIUM
CVE-2022-3562
< 22.10.0
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
5.4MEDIUM
CVE-2022-3561
< 22.10.0
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.
6.1MEDIUM
CVE-2022-3525
< 22.10.0
Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.
8.8HIGH
CVE-2022-3516
< 22.10.0
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
6.1MEDIUM
CVE-2022-3231
< 22.9.0
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0.
5.4MEDIUM
CVE-2022-36746
all versions
LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php
6.1MEDIUM
CVE-2022-36745
all versions
LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php.
6.1MEDIUM
CVE-2022-29712
all versions
LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_pa
9.8CRITICAL
CVE-2022-29711
all versions
LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogController.p
6.1MEDIUM
CVE-2022-0772
< 22.2.2
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.2.2.
4.8MEDIUM
CVE-2022-0589
< 22.1.0
Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0.
5.4MEDIUM
CVE-2022-0588
< 22.2.0
Missing Authorization in Packagist librenms/librenms prior to 22.2.0.
7.1HIGH
CVE-2022-0587
< 22.2.0
Improper Authorization in Packagist librenms/librenms prior to 22.2.0.
6.5MEDIUM
CVE-2022-0580
< 22.2.0
Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.
7.1HIGH
CVE-2022-0576
< 22.2.0
Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0.
6.1MEDIUM
CVE-2022-0575
< 22.2.0
Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0.
5.4MEDIUM
CVE-2021-44278
all versions
Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.
9.8CRITICAL
CVE-2021-44279
all versions
Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php.
6.1MEDIUM
CVE-2021-44277
all versions
Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/common/alert-log.inc.php.
6.1MEDIUM
CVE-2021-43324
<= 21.10.2
LibreNMS through 21.10.2 allows XSS via a widget title.
6.1MEDIUM
CVE-2021-31274
< 21.3.0
In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $ap
5.4MEDIUM
CVE-2020-35700
< 21.1.0
A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 2
8.8HIGH
CVE-2020-15877
< 1.65.1
An issue was discovered in LibreNMS before 1.65.1. It has insufficient access control for normal users because of "'guard' => 'adm
8.8HIGH
CVE-2020-15873
< 1.65.1
In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter
6.5MEDIUM
CVE-2019-12465
< 1.53
An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where the term pa
8.1HIGH
CVE-2019-12464
all versions
An issue was discovered in LibreNMS 1.50.1. An authenticated user can perform a directory traversal attack against the /pdf.php fi
7.5HIGH
CVE-2019-12463
>= 1.50.1 and < 1.53
An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and incl
8.8HIGH
CVE-2019-10671
<= 1.47
An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queries, result
8.8HIGH
CVE-2019-10670
<= 1.47
An issue was discovered in LibreNMS through 1.47. Many of the scripts rely on the function mysqli_escape_real_string for filtering
6.1MEDIUM
CVE-2019-10669
<= 1.47
An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/device/collec
7.2HIGH
CVE-2019-10668
<= 1.47
An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an a
9.1CRITICAL
CVE-2019-10667
<= 1.47
An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code ver
5.3MEDIUM
CVE-2019-10666
<= 1.47
An issue was discovered in LibreNMS through 1.47. Several of the scripts perform dynamic script inclusion via the include() functi
8.1HIGH
CVE-2019-10665
<= 1.47
An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.ph
9.8CRITICAL
CVE-2019-15230
all versions
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Templat
5.4MEDIUM
CVE-2018-20434
all versions
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/ad
9.8CRITICAL
CVE-2018-20678
<= 1.47
LibreNMS through 1.47 allows SQL injection via the html/ajax_table.php sort[hostname] parameter, exploitable by authenticated user
8.8HIGH
CVE-2018-18478
< 1.44
Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML
6.1MEDIUM
CVE-2017-16759
<= 1.30
The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.ph
5.9MEDIUM
threatengine.sh