librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. This allows a user with the admin role to inject malicious JavaScript, which will be executed when the template is rendered, potentially compromising other admin accounts. This vulnerability is fixed in 25.8.0.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Librenms
Librenms librenms |
|
Vendors & Products |
Librenms
Librenms librenms |
Mon, 18 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 18 Aug 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. This allows a user with the admin role to inject malicious JavaScript, which will be executed when the template is rendered, potentially compromising other admin accounts. This vulnerability is fixed in 25.8.0. | |
Title | LibreNMS allows stored XSS in Alert Template name field | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-18T17:27:52.662Z
Updated: 2025-08-18T17:38:16.117Z
Reserved: 2025-08-12T16:15:30.238Z
Link: CVE-2025-55296

Updated: 2025-08-18T17:38:03.707Z

Status : Awaiting Analysis
Published: 2025-08-18T18:15:39.810
Modified: 2025-08-18T20:16:28.750
Link: CVE-2025-55296

No data.