Vulnerabilities in LibreNMS
88 resultsVexday analysis
LibreNMS apresenta um perfil de risco baixo com apenas 1 vulnerabilidade registrada na base, sem evidência de exploração ativa em campo. A fraqueza identificada (CWE-89 - SQL Injection) é clássica e não recente, sugerindo que a questão já foi abordada ou permanece sem impacto crítico comprovado. Recomenda-se acompanhamento rotineiro, mas não há sinais de urgência operacional.
CVE-2024-51497MEDIUMLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/print-customoid.phpEPSS 0.4%CVE-2024-51494MEDIUMLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.phpEPSS 0.4%CVE-2024-51495MEDIUMLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/dev-overview-data.inc.phpEPSS 0.4%CVE-2024-50351MEDIUMLibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/functions.phpEPSS 0.4%CVE-2024-50350MEDIUMLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.phpEPSS 0.4%CVE-2024-49764MEDIUMLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/capture.inc.phpEPSS 0.4%CVE-2024-56144MEDIUMStored XSS-LibreNMS-Display Name 2 in librenmsEPSS 0.4%CVE-2025-23198MEDIUMStored-XSS-LibreNMS-Display-Name in librenmsEPSS 0.4%CVE-2024-49758MEDIUMLibreNMS has a stored XSS in ExamplePlugin with Device's NotesEPSS 0.3%CVE-2026-86427HIGHLibreNMS before 26.8.0 Argument Injection via graph_titleEPSS 0.3%CVE-2024-50355MEDIUMLibreNMS has a Persistent XSS from Insecure Input Sanitization Affects Multiple EndpointsEPSS 0.3%CVE-2026-26987MEDIUMLibreNMS affected by reflected XSS via email fieldEPSS 0.3%CVE-2020-15875MEDIUMAn issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LiEPSS 0.3%CVE-2025-62412LOWLibreNMS alert-rules Cross-Site Scripting VulnerabilityEPSS 0.3%CVE-2026-84193MEDIUMLibreNMS through 26.2.0 Stored Cross-Site Scripting via SNMPEPSS 0.3%CVE-2026-84189CRITICALLibreNMS before 26.7.0 Stored XSS via Oxidized APIEPSS 0.3%CVE-2025-65014LOWLibreNMS has Weak Password PolicyEPSS 0.3%CVE-2025-65013MEDIUMLibreNMS vulnerable to Reflected Cross-Site Scripting (XSS) in endpoint `/maps/nodeimage` parameter `Image Name`EPSS 0.3%CVE-2026-26989MEDIUMLibreNMS has Stored XSS in Alert RuleEPSS 0.2%CVE-2025-62365MEDIUMLibreNMS vulnerable to Reflected-XSS in `report_this` functionEPSS 0.2%