Cross-site scripting in LibreNMS - #VU140835
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in includes/html/pages/graphs.inc.php when rendering graph description settings. A remote privileged user can store a malicious HTML payload in the graph_descr.
User interaction is required to view a graph of the affected type.