Librenms/librenms
This hub aggregates every CVE we track for Librenms/librenms, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
98
CVEs tracked
8
Critical
21
High
0
In CISA KEV
Severity distribution
MEDIUM66HIGH21CRITICAL8LOW3
Monthly trend
0
0
0
6
13
1
5
0
0
0
1
0
1
1
0
3
3
1
1
7
0
0
1
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Librenms/librenms.
- CVE-2024-51092LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.php's update(), and PollDevice.php's ...9.1
- CVE-2026-26992LibreNMS has Stored Cross-Site Scripting via unsanitized /port-groups name4.8
- CVE-2026-26991LibreNMS vulnerable to Stored Cross-site Scripting through unsanitized /device-groups name4.8
- CVE-2026-27016LibreNMS has Stored XSS in Custom OID - unit parameter missing strip_tags()5.4
- CVE-2026-26990LibreNMS has Time-Based Blind SQL Injection in address-search.inc.php8.8
- CVE-2026-26989LibreNMS has Stored XSS in Alert Rule4.3
- CVE-2026-26988LibreNMS: SQL Injection in ajax_table.php spreads through a covert data stream9.1
- CVE-2026-26987LibreNMS affected by reflected XSS via email field6.1
- CVE-2020-36947LibreNMS 1.46 - MAC Accounting Graph Authenticated SQL Injection7.1
- CVE-2025-68614LibreNMS Alert Rule API Cross-Site Scripting Vulnerability4.3
- CVE-2025-65093LibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.php endpoint5.5
- CVE-2025-65014LibreNMS has Weak Password Policy3.7
- CVE-2025-65013LibreNMS vulnerable to Reflected Cross-Site Scripting (XSS) in endpoint `/maps/nodeimage` parameter `Image Name`6.2
- CVE-2025-62412LibreNMS alert-rules Cross-Site Scripting Vulnerability3.8
- CVE-2025-62411Stored XSS in Alert Transport name field in LibreNMS5.5
Product normalization is registry-driven with AI assist and human review. How it works