← Vulnerability feed

Vulnerability record · CVE-2025-62411 · published 16 October 2025

CVE-2025-62411: Librenms cross-site scripting vulnerability

Librenms · Librenms

LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When an administrator creates a new Alert Transport, the value of the Transport name field is stored and later rendered in the Transports column of the Alert Rules page without proper input validation or output encoding. This leads to arbitrary JavaScript execution in the admin’s browser. This vulnerability is fixed in 25.10.0.

4.8 CVSS 3.1 Medium EPSS 13% · top 3.9% CWE-79 · Cross-site scripting
4.8CVSS 3.1 base score
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When an administrator creates a new Alert Transport, the value of the Transport name field is stored and later rendered in the Transports column of the Alert Rules page without proper input validation or output encoding. This leads to arbitrary JavaScript execution in the admin’s browser. This vulnerability is fixed in 25.10.0.

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-62411 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-4070Librenms insufficient session expiration vulnerabilityInsufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.EPSS 0.65%9.8CVE-2022-29712Librenms command injection vulnerabilityLibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters.EPSS 1.7%9.8CVE-2021-44278Librenms path traversal vulnerabilityLibrenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.EPSS 1.5%9.8CVE-2019-10665Librenms injection vulnerabilityAn issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes…EPSS 1.5%9.8CVE-2018-20434LibreNMS addhost OS command injection via community parameterLibreNMS 1.46 fails to sanitize the $_POST['community'] parameter in html/pages/addhost.inc.php when creating a new device, and the value is later mi…EPSS 71%analysed9.3CVE-2026-26988Librenms sql injection vulnerabilityLibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in th…EPSS 0.48%9.2CVE-2026-86426Librenms improper authentication vulnerabilityLibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endp…EPSS 3.9%9.1CVE-2024-51092Librenms os command injection vulnerabilityLibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), Settings…EPSS 7.2%

Source: NIST National Vulnerability Database (record CVE-2025-62411), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.