← Vulnerability feed

Vulnerability record · CVE-2022-3562 · published 20 November 2022

CVE-2022-3562: LibreNMS stored XSS before 22.10.0

Librenms · Librenms

LibreNMS versions prior to 22.10.0 contain a stored cross-site scripting flaw (CWE-79). An attacker with a low-privileged account can inject script that is stored and later rendered to other users, which matters because it can run in the context of higher-privileged sessions.

5.4 CVSS 3.1 Medium EPSS 94% · top 0.2% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityCVSS rates it medium (5.4) and it requires authentication plus user interaction, though the very high EPSS score warrants prompt patching.

What it is

LibreNMS versions prior to 22.10.0 contain a stored cross-site scripting flaw (CWE-79). An attacker with a low-privileged account can inject script that is stored and later rendered to other users, which matters because it can run in the context of higher-privileged sessions.

Impact

An attacker can execute arbitrary script in the browser of a victim who views the injected content, potentially stealing session data or performing actions as that user. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.

Attack surface

Reached over the network (AV:N) with low privileges required (PR:L) and user interaction needed (UI:R) for the victim to trigger the stored payload. No unauthenticated access is implied by the vector.

Exploitation

Not listed in CISA KEV and no ransomware usage documented; EPSS is very high (0.94216, 99.8th percentile), and references include a patch commit and a huntr bounty marked Permissions Required.

What to do

  • Upgrade LibreNMS to 22.10.0 or later, applying the referenced patch commit.
  • Restrict accounts and permissions so only trusted users can create or edit content that is rendered to others.
  • Apply output encoding and input sanitization for stored user-supplied fields.
  • Monitor for suspicious script content in stored fields and review recent changes by low-privileged accounts.

Detection

  • Search application logs and stored content for script tags or event handlers in user-supplied fields.
  • Alert on anomalous session activity or requests originating from pages containing stored user content.
  • Review huntr bounty and patch commit details to build targeted signatures for the affected input paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-3562 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-4070Librenms insufficient session expiration vulnerabilityInsufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.EPSS 0.65%9.8CVE-2022-29712Librenms command injection vulnerabilityLibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters.EPSS 1.7%9.8CVE-2021-44278Librenms path traversal vulnerabilityLibrenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.EPSS 1.5%9.8CVE-2019-10665Librenms injection vulnerabilityAn issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes…EPSS 1.5%9.8CVE-2018-20434LibreNMS addhost OS command injection via community parameterLibreNMS 1.46 fails to sanitize the $_POST['community'] parameter in html/pages/addhost.inc.php when creating a new device, and the value is later mi…EPSS 71%analysed9.3CVE-2026-26988Librenms sql injection vulnerabilityLibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in th…EPSS 0.48%9.2CVE-2026-86426Librenms improper authentication vulnerabilityLibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endp…EPSS 3.9%9.1CVE-2024-51092Librenms os command injection vulnerabilityLibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), Settings…EPSS 7.2%

Source: NIST National Vulnerability Database (record CVE-2022-3562), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.