VulnSea

librenms/librenms vulnerabilities

CVEs whose affected-version data names the librenms/librenms package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

GHSA-7w8c-qgxg-m7jxHigh· 7.1
3w ago

LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates

LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates

Twilightlibrenms · librenms/librenmsvia GHSA
CVE-2026-55182High
3w ago

LibreNMS is a network monitoring system

LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection because the signal-cli path and the Recipient field of an alert transport entry are insufficient…

Twilightlibrenms · librenms/librenmsEPSS 1.1%via NVD
CVE-2026-45694Medium· 5.4
3w ago

LibreNMS is a network monitoring system

LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected…

Sunlitlibrenms · librenms/librenmsEPSS 0.15%via NVD
GHSA-jf24-8g2h-2wg7Medium
1mo ago

LibreNMS Vulnerable to Remote Code Execution via AboutController

LibreNMS Vulnerable to Remote Code Execution via AboutController

Sunlitlibrenms · librenms/librenmsvia GHSA
GHSA-7cj5-v4pp-v632Medium· 4.8
1mo ago

LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users

LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users

Sunlitlibrenms · librenms/librenmsvia GHSA
GHSA-7gww-x7fh-jf9jHigh· 8.1
1mo ago

LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page

LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page

Twilightlibrenms · librenms/librenmsvia GHSA
librenms/librenms vulnerabilities (CVEs) · VulnSea