librenms has 9 CVEs on record. Disclosure cadence is accelerating: 9 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 6. The median CVSS is 7.1 (high), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (4) and CWE-77 (3). Most affected products: librenms/librenms (6), LibreNMS (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 9 prev 0
Worst active — by depth score
CVE-2026-86426Critical· 9.8LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens66CVE-2026-86427High· 8.8LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments by breaking out of double-quote escaping48GHSA-7gww-x7fh-jf9jHigh· 8.1LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page45CVE-2026-55182HighLibreNMS is a network monitoring system41CVE-2020-15875Medium· 5.0An issue was discovered in LibreNMS 1.6540
librenms vulnerabilities
CVEs affecting librenms, newest first. Open any entry for full detail, references, and exploit status.
9 CVEsRSS
CVE-2020-15875Medium· 5.0PoCAn issue was discovered in LibreNMS 1.65
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endp…
CVE-2026-86427High· 8.8LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments by breaking out of double-quote escaping
LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments by breaking out of double-quote escaping. Attackers can inject DEF…
CVE-2026-86426Critical· 9.8PoCLibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens
LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL ty…
GHSA-7w8c-qgxg-m7jxHigh· 7.1LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates
LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates
CVE-2026-55182HighLibreNMS is a network monitoring system
LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection because the signal-cli path and the Recipient field of an alert transport entry are insufficient…
CVE-2026-45694Medium· 5.4LibreNMS is a network monitoring system
LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected…
GHSA-jf24-8g2h-2wg7MediumLibreNMS Vulnerable to Remote Code Execution via AboutController
LibreNMS Vulnerable to Remote Code Execution via AboutController
GHSA-7cj5-v4pp-v632Medium· 4.8LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users
LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users
GHSA-7gww-x7fh-jf9jHigh· 8.1LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page
LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page