Vulnerabilities in librenms

75 results
Vexday analysis

O LibreNMS acumula 74 CVEs catalogadas, sem nenhuma confirmada em exploração ativa no catálogo CISA KEV — taxa abaixo da média geral do catálogo. Ainda assim, o cenário merece atenção: a CVE mais perigosa identificada, CVE-2022-3562, apresenta EPSS de 0,9422, indicando altíssima probabilidade estatística de exploração, e há 2 vulnerabilidades com PoC pública disponível, o que reduz a barreira técnica para atacantes. A falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode ser encadeado com outras fraquezas para escalada de impacto em aplicações de monitoramento de rede com acesso privilegiado. Equipes que mantêm instâncias do LibreNMS devem priorizar a remediação da CVE-2022-3562 e revisar exposições relacionadas a XSS, especialmente em ambientes acessíveis externamente.

CVE-2022-3562MEDIUMCross-site Scripting (XSS) - Stored in librenms/librenmsEPSS 94.2%CVE-2022-4067LOWCross-site Scripting (XSS) - Stored in librenms/librenmsEPSS 93.7%CVE-2022-4069LOWCross-site Scripting (XSS) - Generic in librenms/librenmsEPSS 93.3%CVE-2024-49754HIGHLibreNMS has a stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/api-access.inc.phpEPSS 69.8%CVE-2023-4347HIGHCross-site Scripting (XSS) - Reflected in librenms/librenmsEPSS 66.9%CVE-2024-50352MEDIUMLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/overview/services.inc.phpEPSS 36.7%CVE-2024-32479HIGHLibreNMS's Improper Sanitization on Service template name leads to Stored XSSEPSS 34.1%CVE-2022-4068HIGHImproperly Controlled Modification of Dynamically-Determined Object Attributes in librenms/librenmsEPSS 34.0%CVE-2025-23200MEDIUMStored XSS-LibreNMS-Misc Section in librenmsEPSS 30.9%CVE-2024-47525HIGHStored XSS ('Cross-site Scripting') in librenms/includes/html/print-alert-rules.phpEPSS 26.6%CVE-2023-5591HIGHSQL Injection in librenms/librenmsEPSS 22.2%CVE-2024-32480HIGHLibreNMS's Time-Based Blind SQL injection leads to database extractionEPSS 20.3%CVE-2024-32461HIGHLibreNMS vulnerable to time-based SQL injection that leads to database extractionEPSS 19.1%CVE-2025-62411MEDIUMStored XSS in Alert Transport name field in LibreNMSEPSS 11.9%CVE-2025-55296MEDIUMLibreNMS allows stored XSS in Alert Template name fieldEPSS 11.9%CVE-2026-6204HIGHLibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config EPSS 7.5%CVE-2026-26988CRITICALLibreNMS: SQL Injection in ajax_table.php spreads through a covert data streamEPSS 7.4%CVE-2026-26990HIGHLibreNMS has Time-Based Blind SQL Injection in address-search.inc.phpEPSS 4.1%CVE-2025-65093MEDIUMLibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.php endpointEPSS 3.6%CVE-2025-68614MEDIUMLibreNMS Alert Rule API Cross-Site Scripting VulnerabilityEPSS 3.5%