Cross-site scripting in LibreNMS - #VU134531
Published: June 15, 2026
LibreNMS
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary JavaScript in a victim's browser session.
The vulnerability exists due to cross-site scripting in legacy PHP templates under includes/html/ when rendering SNMP-sourced and syslog-sourced data. A remote attacker can supply crafted device metadata or syslog fields to execute arbitrary JavaScript in a victim's browser session.
User interaction is required to view an affected page, and the attacker must control a monitored SNMP device or a syslog source.