VulnSea

librenms has 9 CVEs on record. Disclosure cadence is accelerating: 9 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 6. The median CVSS is 7.1 (high), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (4) and CWE-77 (3). Most affected products: librenms/librenms (6), LibreNMS (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.1
Publish → KEV
Last 90 days
9 prev 0

Products

  • librenms/librenms 6
  • LibreNMS 3
9
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

librenms vulnerabilities

CVEs affecting librenms, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2020-15875Medium· 5.0PoC
1w ago

An issue was discovered in LibreNMS 1.65

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endp…

TwilightLibreNMS · LibreNMSEPSS 0.28%via NVD
CVE-2026-86427High· 8.8
2w ago

LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments by breaking out of double-quote escaping

LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments by breaking out of double-quote escaping. Attackers can inject DEF…

Twilightlibrenms · librenmsEPSS 0.33%via NVD
CVE-2026-86426Critical· 9.8PoC
2w ago

LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens

LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL ty…

Abyssallibrenms · librenmsEPSS 2.1%via NVD
GHSA-7w8c-qgxg-m7jxHigh· 7.1
3w ago

LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates

LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates

Twilightlibrenms · librenms/librenmsvia GHSA
CVE-2026-55182High
3w ago

LibreNMS is a network monitoring system

LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection because the signal-cli path and the Recipient field of an alert transport entry are insufficient…

Twilightlibrenms · librenms/librenmsEPSS 1.1%via NVD
CVE-2026-45694Medium· 5.4
3w ago

LibreNMS is a network monitoring system

LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected…

Sunlitlibrenms · librenms/librenmsEPSS 0.15%via NVD
GHSA-jf24-8g2h-2wg7Medium
1mo ago

LibreNMS Vulnerable to Remote Code Execution via AboutController

LibreNMS Vulnerable to Remote Code Execution via AboutController

Sunlitlibrenms · librenms/librenmsvia GHSA
GHSA-7cj5-v4pp-v632Medium· 4.8
1mo ago

LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users

LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users

Sunlitlibrenms · librenms/librenmsvia GHSA
GHSA-7gww-x7fh-jf9jHigh· 8.1
1mo ago

LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page

LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page

Twilightlibrenms · librenms/librenmsvia GHSA
librenms vulnerabilities (CVEs) · VulnSea