ZeroHour

Vulnerabilities

104 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-51092
LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.

LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.php's update(), and PollDevice.php's initRrdDirectory().

NVD description · AI analysis pending
9.17% PoC ×2
  • librenms librenms
CVE-2026-6204
+1 in the same advisory: …2728
LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand f

LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could result in compromise of the underlying web server.

NVD description · AI analysis pending
8.5
group max
8% PoC
  • librenms librenms
CVE-2026-26988
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool.

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in the ajax_table.php endpoint. The application fails to properly sanitize or parameterize user input when processing IPv6 address searches. Specifically, the address parameter is split into an address and a prefix, and the prefix portion is directly concatenated into the SQL query string without validation. This allows an attacker to inject arbitrary SQL commands, potentially leading to unauthorized data access or database manipulation. This issue has been fixed in version 26.2.0.

NVD description · AI analysis pending
9.3
group max
7% PoC
  • librenms librenms
CVE-2020-36947
LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract database inform

LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract database information. Attackers can exploit the vulnerability by manipulating the 'sort' parameter with crafted SQL injection techniques to retrieve sensitive database contents through time-based blind SQL injection.

NVD description · AI analysis pending
7.1<1% PoC
  • librenms librenms
CVE-2025-68614
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool.

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule API is vulnerable to stored cross-site scripting. Alert rules can be created or updated via LibreNMS API. The alert rule name is not properly sanitized, and can be used to inject HTML code. This issue has been patched in version 25.12.0.

NVD description · AI analysis pending
5.44% PoC
  • librenms librenms
CVE-2025-65013
+2 in the same advisory: …65093 …65014
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool.

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scripting (XSS) vulnerability was identified in the LibreNMS application at the /maps/nodeimage endpoint. The Image Name parameter is reflected in the HTTP response without proper output encoding or sanitization, allowing an attacker to craft a URL that, when visited by a victim, causes arbitrary JavaScript execution in the victim’s browser. This issue has been patched in version 25.11.0.

NVD description · AI analysis pending
6.1
group max
<1%
  • librenms librenms
CVE-2025-62411
+1 in the same advisory: …62412
LibreNMS is a community-based GPL-licensed network monitoring system.

LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When an administrator creates a new Alert Transport, the value of the Transport name field is stored and later rendered in the Transports column of the Alert Rules page without proper input validation or output encoding. This leads to arbitrary JavaScript execution in the admin’s browser. This vulnerability is fixed in 25.10.0.

NVD description · AI analysis pending
4.812% PoC
  • librenms librenms
CVE-2025-62365
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system.

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in `report_this` function in `librenms/includes/functions.php`. The `report_this` function had improper filtering (`htmlentities` function was incorrectly use in a href environment), which caused the `project_issues` parameter to trigger an XSS vulnerability. This vulnerability is fixed in 25.7.0.

NVD description · AI analysis pending
5.5<1% PoC
  • librenms librenms
CVE-2025-55296
librenms is a community-based GPL-licensed network monitoring system.

librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. This allows a user with the admin role to inject malicious JavaScript, which will be executed when the template is rendered, potentially compromising other admin accounts. This vulnerability is fixed in 25.8.0.

NVD description · AI analysis pending
5.412% PoC
  • librenms librenms
CVE-2025-54138
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems.

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. LibreNMS versions 25.6.0 and below contain an architectural vulnerability in the ajax_form.php endpoint that permits Remote File Inclusion based on user-controlled POST input. The application directly uses the type parameter to dynamically include .inc.php files from the trusted path includes/html/forms/, without validation or allowlisting. This pattern introduces a latent Remote Code Execution (RCE) vector if an attacker can stage a file in this include path — for example, via symlink, development misconfiguration, or chained vulnerabilities. This is fixed in version 25.7.0.

NVD description · AI analysis pending
7.51% PoC
  • librenms librenms
CVE-2025-47931
LibreNMS is PHP/MySQL/SNMP based network monitoring software.

LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scripting (XSS) Vulnerability in the `group name` parameter of the `http://localhost/poller/groups` form. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users. LibreNMS v25.5.0 contains a patch for the issue.

NVD description · AI analysis pending
2.112% PoC
  • librenms librenms
CVE-2025-23201
+4 in the same advisory: …23200 …23199 …56144 …23198
librenms is a community-based GPL-licensed network monitoring system.

librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to Cross-site Scripting (XSS) on the parameters:`/addhost` -> param: community. Librenms versions up to 24.10.1 allow remote attackers to inject malicious scripts. When a user views or interacts with the page displaying the data, the malicious script executes immediately, leading to potential unauthorized actions or data exposure. This issue has been addressed in release version 24.11.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • librenms librenms
CVE-2024-53457
Stored XSS in LibreNMS Device Settings Display Name

CVE-2024-53457 is a stored cross-site scripting (XSS) flaw in the Device Settings section of the LibreNMS network monitoring platform, versions v24.9.0 through v24.10.0. An authenticated user with access to device settings can inject a crafted payload into the Display Name parameter, and the malicious script or HTML is then persistently stored and executed when other users view the affected device page. An attacker gains the ability to run arbitrary web scripts in the browsers of other LibreNMS users, under the application's origin, which can be used for session or credential theft and other client-side attacks given the low-privilege, user-interaction requirements reflected in the CVSS score. Organizations running LibreNMS v24.9.0 to v24.10.0 are affected; instances on older or newer releases fall outside the published range. A public proof-of-concept exists and EPSS assigns a high ~44% probability of exploitation within 30 days, but the flaw is not yet in CISA KEV and there is no confirmed in-the-wild exploitation.

Do: Upgrade LibreNMS to a release newer than v24.10.0, which exits the affected range. In the meantime, restrict who can edit Device Settings, review stored device Display Names for embedded HTML/script payloads, and ensure output escaping of the Display Name field is applied if patching is delayed.

5.445% PoC
  • librenms v24.9.0 through v24.10.0 (inclusive)
moderateroughly 1,000–10,000 deployments (only those running the narrow v24.9.0–v24.10.0 release window are affected)
CVE-2024-49754
Stored XSS in LibreNMS API-Access page risks session hijack

LibreNMS, an open-source PHP/MySQL/SNMP network monitoring system, contains a stored cross-site scripting (XSS) flaw (CWE-79) in its API-Access page. An authenticated user with low privileges can embed arbitrary JavaScript in the token field when creating a new API token; the payload is saved and later executes in the browsers of other users who view that page, requiring user interaction to trigger. Successful exploitation runs attacker-supplied code in the context of other users' sessions, which can lead to account compromise and unauthorized actions within the monitoring platform. All LibreNMS deployments running versions prior to 24.10.0 are affected. The flaw is not yet in CISA's KEV catalog, but a public advisory exists and EPSS assigns a high 71.1% probability of exploitation within 30 days (99th percentile), indicating elevated near-term risk.

Do: Upgrade to LibreNMS 24.10.0 or later. Until patched, restrict API token creation to trusted users and review existing tokens for unexpected or script-bearing values, removing or rotating any suspicious ones. Because injected scripts execute in other users' sessions, also review user activity logs for unexpected actions following recent token creation.

5.4
group max
71% PoC
  • librenms all versions prior to 24.10.0 (fixed in 24.10.0)
moderatetens of thousands of self-hosted deployments worldwide (order-of-magnitude estimate)
CVE-2024-47525
Stored XSS in LibreNMS Alert Rules lets authenticated users hijack sessions

LibreNMS, an open-source PHP/MySQL/SNMP-based network monitoring system, contains a stored cross-site scripting (XSS) flaw (CWE-79) in its Alert Rules feature. An authenticated user can inject arbitrary JavaScript into the 'Title' field of an alert rule; the script then executes in the browsers of other users who view that rule, running in the context of their sessions. Successful exploitation can compromise other users' accounts and enable unauthorized actions within LibreNMS, though the network vector requires low privileges and user interaction (CVSS 3.1: 5.4, Scope: Changed). All LibreNMS deployments running versions before 24.9.0 are affected, with internet-exposed instances facing the greatest risk from lower-privileged or malicious insiders and compromised accounts. As of now there is no CISA KEV listing, but one public reference (the GitHub security advisory GHSA-j2j9-7pr6-xqwv) documents the issue, and EPSS assigns a relatively high 29.6% probability of exploitation within 30 days.

Do: Upgrade LibreNMS to 24.9.0 or later, which fixes the issue. Until then, restrict creation and editing of Alert Rules to trusted administrator accounts, review existing alert rule titles for injected HTML/JavaScript, and consider sanitizing the Title field at the web application firewall or reverse-proxy layer for internet-exposed instances.

5.4
group max
30% PoC
  • LibreNMS all versions prior to 24.9.0 (fixed in 24.9.0)
moderatelikely on the order of tens of thousands of self-hosted instances, of which only thousands are internet-exposed
CVE-2024-32461
+2 in the same advisory: …32480 …32479
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system.

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A SQL injection vulnerability in POST /search/search=packages in LibreNMS prior to version 24.4.0 allows a user with global read privileges to execute SQL commands via the package parameter. With this vulnerability, an attacker can exploit a SQL injection time based vulnerability to extract all data from the database, such as administrator credentials. Version 24.4.0 contains a patch for the vulnerability.

NVD description · AI analysis pending
8.8
group max
19% PoC ×2
  • librenms librenms
CVE-2023-48294
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems.

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions of LibreNMS when a user accesses their device dashboard, one request is sent to `graph.php` to access graphs generated on the particular Device. This request can be accessed by a low privilege user and they can enumerate devices on librenms with their id or hostname. Leveraging this vulnerability a low privilege user can see all devices registered by admin users. This vulnerability has been addressed in commit `489978a923` which has been included in release version 23.11.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

NVD description · AI analysis pending
4.3<1% PoC
  • librenms librenms