Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

librenms — Vulnerabilities & Security Advisories 63

All 63 CVE vulnerabilities found in librenms, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting the open-source network monitoring application LibreNMS. The collection includes critical and high-severity flaws such as remote code execution, cross-site scripting, and information disclosure, covering advisories published from 2019 through the present. Here you can track the vendor's security notices, understand the common weakness classes impacting the product, and review its historical vulnerability timeline to assess risk trends over time.

Vendor: librenms

CVE ID Title CVSS Severity Published
CVE-2020-15875 LibreNMS SQL注入漏洞 CWE-89 5.0 Medium 2026-09-13
CVE-2026-86427 LibreNMS before 26.8.0 Argument Injection via graph_title CWE-77 8.8 High 2026-09-07
CVE-2026-86426 LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion CWE-287 9.2 Critical 2026-09-07
CVE-2026-84194 LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostname CWE-78 8.6 High 2026-09-01
CVE-2026-84193 LibreNMS through 26.2.0 Stored Cross-Site Scripting via SNMP CWE-79 5.8 Medium 2026-09-01
CVE-2026-84191 LibreNMS before 26.5.0 Stored XSS via SNMP VRF fields CWE-79 6.1 Medium 2026-09-01
CVE-2026-84192 LibreNMS before 26.3.1 Stored XSS via SNMP/Syslog Data CWE-79 7.1 High 2026-09-01
CVE-2026-84190 LibreNMS before 26.5.0 Remote Code Execution via AboutController CWE-77 7.2 High 2026-09-01
CVE-2026-84189 LibreNMS before 26.7.0 Stored XSS via Oxidized API CWE-79 8.1 High 2026-09-01
CVE-2026-84188 librenms before 26.7.0 Stored XSS via graph_descr settings CWE-79 4.8 Medium 2026-09-01
CVE-2026-55182 LibreNMS: Remote Code Execution by Signal Alert Transportation Module CWE-77 8.6 High 2026-08-26
CVE-2026-45694 LibreNMS: Reflected XSS in the Proxmox app view via unsanitized instance/vmid parameters CWE-79 5.4 Medium 2026-08-26
CVE-2026-80214 LibreNMS Virtualisation Discovery Module RCE CWE-78 8.6 High 2026-08-26
CVE-2026-6204 LibreNMS 安全漏洞 CWE-78 7.2 - 2026-04-13
CVE-2026-2728 LibreNMS 安全漏洞 CWE-79 4.8 - 2026-04-13
CVE-2026-26992 LibreNMS has Stored Cross-Site Scripting via unsanitized /port-groups name CWE-79 4.8 - 2026-02-20
CVE-2026-26991 LibreNMS vulnerable to Stored Cross-site Scripting through unsanitized /device-groups name CWE-79 4.8 - 2026-02-20
CVE-2026-27016 LibreNMS has Stored XSS in Custom OID - unit parameter missing strip_tags() CWE-79 5.4 Medium 2026-02-20
CVE-2026-26990 LibreNMS has Time-Based Blind SQL Injection in address-search.inc.php CWE-89 8.8 High 2026-02-20
CVE-2026-26989 LibreNMS has Stored XSS in Alert Rule CWE-79 4.3 Medium 2026-02-20
CVE-2026-26988 LibreNMS: SQL Injection in ajax_table.php spreads through a covert data stream CWE-89 9.8 - 2026-02-20
CVE-2026-26987 LibreNMS affected by reflected XSS via email field CWE-79 6.1 - 2026-02-20
CVE-2020-36947 LibreNMS 1.46 - MAC Accounting Graph Authenticated SQL Injection CWE-89 7.1 High 2026-01-27
CVE-2025-68614 LibreNMS Alert Rule API Cross-Site Scripting Vulnerability CWE-79 4.3 Medium 2025-12-22
CVE-2025-65093 LibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.php endpoint CWE-89 5.5 Medium 2025-11-18
CVE-2025-65014 LibreNMS has Weak Password Policy CWE-521 3.7 Low 2025-11-18
CVE-2025-65013 LibreNMS vulnerable to Reflected Cross-Site Scripting (XSS) in endpoint `/maps/nodeimage` parameter `Image Name` CWE-79 6.2 Medium 2025-11-18
CVE-2025-62412 LibreNMS alert-rules Cross-Site Scripting Vulnerability CWE-79 3.8 Low 2025-10-16
CVE-2025-62411 Stored XSS in Alert Transport name field in LibreNMS CWE-79 5.5 Medium 2025-10-16
CVE-2025-62365 LibreNMS vulnerable to Reflected-XSS in `report_this` function CWE-79 6.1AI Medium AI 2025-10-13

All 63 known CVE vulnerabilities affecting librenms with full Chinese analysis, references, and POCs where available.