CVE-2026-30480
- EPSS 0.02%
- Veröffentlicht 14.04.2026 00:00:00
- Zuletzt bearbeitet 17.04.2026 15:24:57
A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesystem via path traversal sequences in the nfsen parame...
CVE-2026-6204
- EPSS 0.01%
- Veröffentlicht 13.04.2026 10:56:16
- Zuletzt bearbeitet 13.04.2026 15:01:43
LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could res...
CVE-2026-2728
- EPSS 0%
- Veröffentlicht 13.04.2026 10:39:54
- Zuletzt bearbeitet 13.04.2026 15:01:43
LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against o...
CVE-2026-26992
- EPSS 0%
- Veröffentlicht 20.02.2026 03:16:00
- Zuletzt bearbeitet 20.02.2026 16:20:34
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the port group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a us...
CVE-2026-26991
- EPSS 0%
- Veröffentlicht 20.02.2026 03:15:59
- Zuletzt bearbeitet 20.02.2026 16:21:10
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the device group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a ...
CVE-2026-27016
- EPSS 0%
- Veröffentlicht 20.02.2026 02:16:55
- Zuletzt bearbeitet 20.02.2026 16:22:29
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other ...
CVE-2026-26989
- EPSS 0%
- Veröffentlicht 20.02.2026 02:16:54
- Zuletzt bearbeitet 20.02.2026 16:25:20
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are affected by a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Rules workflow. An attacker with administrative privileges can inj...
CVE-2026-26990
- EPSS 0%
- Veröffentlicht 20.02.2026 02:16:54
- Zuletzt bearbeitet 20.02.2026 16:24:36
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below have a Time-Based Blind SQL Injection vulnerability in address-search.inc.php via the address parameter. When a crafted subnet prefix is supplied...
CVE-2026-26988
- EPSS 0%
- Veröffentlicht 20.02.2026 01:17:15
- Zuletzt bearbeitet 20.02.2026 16:31:42
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in the ajax_table.php endpoint. The application fails to properly sanitize or parameterize user input when...
CVE-2026-26987
- EPSS 0%
- Veröffentlicht 20.02.2026 01:11:13
- Zuletzt bearbeitet 20.02.2026 16:32:16
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to Reflected XSS attacks via email field. This issue has been fixed in version 26.2.0.