Cross-site scripting in LibreNMS - CVE-2025-47931
Published: April 24, 2026
LibreNMS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the poller group name parameter of the /poller/groups form when handling user-supplied poller group names. A remote user can create a poller group with a crafted group name to execute arbitrary script in a victim's browser.
The distributed poller feature must be enabled, and user interaction is required when another user visits the add host page.