CVE-2026-26992
- EPSS 0.01%
- Veröffentlicht 20.02.2026 03:16:00
- Zuletzt bearbeitet 20.02.2026 16:20:34
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the port group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a us...
CVE-2026-26991
- EPSS 0.01%
- Veröffentlicht 20.02.2026 03:15:59
- Zuletzt bearbeitet 20.02.2026 16:21:10
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the device group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a ...
CVE-2026-27016
- EPSS 0.01%
- Veröffentlicht 20.02.2026 02:16:55
- Zuletzt bearbeitet 20.02.2026 16:22:29
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other ...
CVE-2026-26989
- EPSS 0%
- Veröffentlicht 20.02.2026 02:16:54
- Zuletzt bearbeitet 20.02.2026 16:25:20
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are affected by a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Rules workflow. An attacker with administrative privileges can inj...
CVE-2026-26990
- EPSS 0.01%
- Veröffentlicht 20.02.2026 02:16:54
- Zuletzt bearbeitet 20.02.2026 16:24:36
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below have a Time-Based Blind SQL Injection vulnerability in address-search.inc.php via the address parameter. When a crafted subnet prefix is supplied...
CVE-2026-26988
- EPSS 0%
- Veröffentlicht 20.02.2026 01:17:15
- Zuletzt bearbeitet 20.02.2026 16:31:42
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in the ajax_table.php endpoint. The application fails to properly sanitize or parameterize user input when...
CVE-2026-26987
- EPSS 0%
- Veröffentlicht 20.02.2026 01:11:13
- Zuletzt bearbeitet 20.02.2026 16:32:16
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to Reflected XSS attacks via email field. This issue has been fixed in version 26.2.0.
CVE-2020-36947
- EPSS 0.01%
- Veröffentlicht 27.01.2026 15:23:49
- Zuletzt bearbeitet 02.02.2026 19:48:55
LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract database information. Attackers can exploit the vulnerability by manipulating the 'sort' parameter with c...
CVE-2025-68614
- EPSS 0%
- Veröffentlicht 22.12.2025 23:43:02
- Zuletzt bearbeitet 02.01.2026 18:23:30
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule API is vulnerable to stored cross-site scripting. Alert rules can be created or updated via LibreNMS API. The alert rule name is no...
CVE-2025-65093
- EPSS 0%
- Veröffentlicht 18.11.2025 23:02:04
- Zuletzt bearbeitet 20.11.2025 16:18:22
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application at the /ajax_output.php endpoint. The hostname parame...