LibreNMS

12 known vulnerabilities in LibreNMS, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2020-15875 CVSS 5.0 medium An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the…
  • CVE-2026-86427 CVSS 8.7 high LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to…
  • CVE-2026-86426 CVSS 9.2 critical LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access…
  • CVE-2026-84194 CVSS 8.6 high LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an authenticated OS command injection vulnerability in libvirt…
  • CVE-2026-84193 CVSS 5.8 medium LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped…
  • CVE-2026-84192 CVSS 7.1 high LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and…
  • CVE-2026-84191 CVSS 5.3 medium LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name…
  • CVE-2026-84190 CVSS 8.7 high LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the snmpget configuration…
  • CVE-2026-84189 CVSS 9.2 critical LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized…
  • CVE-2026-84188 CVSS 4.8 medium LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings…
  • CVE-2026-55182 CVSS 8.6 high LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command…
  • CVE-2026-45694 CVSS 5.4 medium LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected…