Cross-site scripting in LibreNMS - CVE-2025-55296
Published: April 24, 2026
LibreNMS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in another administrator's browser.
The vulnerability exists due to cross-site scripting in the Alert Template name field when creating and rendering alert templates. A remote privileged user can submit a crafted template name to execute arbitrary JavaScript in another administrator's browser.
Only administrator accounts that access the Alert Templates page are affected.