Known Vulnerabilities for products from Librenms

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Librenms".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-6204 json LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary L... Not Provided 2026-04-13 2026-04-22
CVE-2026-2728 json LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. S... Not Provided 2026-04-13 2026-04-22
CVE-2024-51092 json LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController... Not Provided 2026-05-08 2026-05-12
CVE-2023-5591 json SQL Injection in GitHub repository librenms/librenms prior to 23.10.0. 6.5 - MEDIUM 2023-10-16 2023-10-19
CVE-2023-5060 json Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1. 6.1 - MEDIUM 2023-09-19 2023-09-19
CVE-2023-4982 json Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0. 5.4 - MEDIUM 2023-09-15 2023-09-20
CVE-2023-4981 json Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0. 5.4 - MEDIUM 2023-09-15 2023-09-20
CVE-2023-4980 json Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0. 5.4 - MEDIUM 2023-09-15 2023-09-20
CVE-2023-4979 json Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0. 5.4 - MEDIUM 2023-09-15 2023-09-20
CVE-2023-4978 json Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0. 6.1 - MEDIUM 2023-09-15 2023-09-20
CVE-2023-4977 json Code Injection in GitHub repository librenms/librenms prior to 23.9.0. 5.4 - MEDIUM 2023-09-15 2023-09-20
CVE-2023-4347 json Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0. 5.4 - MEDIUM 2023-08-15 2023-08-22
CVE-2022-36746 json LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.in... 6.1 - MEDIUM 2022-08-30 2022-09-01
CVE-2022-36745 json LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php. 6.1 - MEDIUM 2022-08-30 2022-09-01
CVE-2022-29712 json LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and servi... 9.8 - CRITICAL 2022-06-02 2022-06-09
CVE-2022-29711 json LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogControl... 6.1 - MEDIUM 2022-06-02 2022-06-09
CVE-2022-4070 json Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0. 9.8 - CRITICAL 2022-11-20 2022-11-21
CVE-2022-4069 json Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0. 4.8 - MEDIUM 2022-11-20 2022-11-21
CVE-2022-4068 json A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreove... 5.4 - MEDIUM 2022-11-20 2022-11-29
CVE-2022-4067 json Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. 5.4 - MEDIUM 2022-11-20 2022-11-21

Known software with vulnerabilities from Librenms

Type Vendor Product Version
ApplicationLibrenmsLibrenms0.1

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report