Vulnerabilities in LibreNMS

88 results
Vexday analysis

LibreNMS apresenta um perfil de risco baixo com apenas 1 vulnerabilidade registrada na base, sem evidência de exploração ativa em campo. A fraqueza identificada (CWE-89 - SQL Injection) é clássica e não recente, sugerindo que a questão já foi abordada ou permanece sem impacto crítico comprovado. Recomenda-se acompanhamento rotineiro, mas não há sinais de urgência operacional.

CVE-2022-3562MEDIUMCross-site Scripting (XSS) - Stored in librenms/librenmsEPSS 94.2%CVE-2022-4067LOWCross-site Scripting (XSS) - Stored in librenms/librenmsEPSS 93.7%CVE-2022-4069LOWCross-site Scripting (XSS) - Generic in librenms/librenmsEPSS 93.3%CVE-2024-49754HIGHLibreNMS has a stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/api-access.inc.phpEPSS 71.1%CVE-2023-4347HIGHCross-site Scripting (XSS) - Reflected in librenms/librenmsEPSS 69.7%CVE-2024-50352MEDIUMLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/overview/services.inc.phpEPSS 37.6%CVE-2022-4068HIGHImproperly Controlled Modification of Dynamically-Determined Object Attributes in librenms/librenmsEPSS 35.9%CVE-2024-32479HIGHLibreNMS's Improper Sanitization on Service template name leads to Stored XSSEPSS 34.1%CVE-2025-23200MEDIUMStored XSS-LibreNMS-Misc Section in librenmsEPSS 30.9%CVE-2024-47525HIGHStored XSS ('Cross-site Scripting') in librenms/includes/html/print-alert-rules.phpEPSS 29.6%CVE-2023-5591HIGHSQL Injection in librenms/librenmsEPSS 22.2%CVE-2024-32480HIGHLibreNMS's Time-Based Blind SQL injection leads to database extractionEPSS 20.3%CVE-2024-32461HIGHLibreNMS vulnerable to time-based SQL injection that leads to database extractionEPSS 19.1%CVE-2025-62411MEDIUMStored XSS in Alert Transport name field in LibreNMSEPSS 12.7%CVE-2025-55296MEDIUMLibreNMS allows stored XSS in Alert Template name fieldEPSS 12.5%CVE-2025-47931LOWLibreNMS stored Cross-site Scripting vulnerability in poller group nameEPSS 11.9%CVE-2026-26988CRITICALLibreNMS: SQL Injection in ajax_table.php spreads through a covert data streamEPSS 7.7%CVE-2026-6204HIGHLibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config EPSS 7.5%CVE-2026-26990HIGHLibreNMS has Time-Based Blind SQL Injection in address-search.inc.phpEPSS 4.1%CVE-2025-68614MEDIUMLibreNMS Alert Rule API Cross-Site Scripting VulnerabilityEPSS 3.9%