Cross-site scripting in LibreNMS - CVE-2025-62365
Published: April 24, 2026
LibreNMS
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script in a user's browser.
The vulnerability exists due to cross-site scripting in the report_this function in librenms/includes/functions.php when handling the project_issues parameter. A remote attacker can supply a specially crafted parameter value to execute arbitrary script in a user's browser.