GHSA-pvwj-jwv3-68wwMediumCVSS 4.8

LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the...

Published
September 1, 2026
Last Modified
September 1, 2026

🔗 CVE IDs covered (1)

📋 Description

LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr. configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrator can store a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type. The issue is fixed in version 26.7.0.

🔗 References (4)