Technology · Librenms
Librenms vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 24 vulnerabilities in Librenms: 0 in the last 7 days and 20 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2020-15875, was published on 13 September 2026.
- Last 7 days
- 0
- Last 90 days
- 20
- Critical, all time
- 2
- Exploited in the wild
- 0
About Librenms
Open-source network monitoring and management application.
Latest Librenms vulnerabilities
- CVE-2020-15875: LibreNMS SQL injection in ajax_table.phpmediumCVSS 5EPSS 0.3%
- CVE-2026-86427: LibreNMS argument injection in graph_title parameterhighCVSS 8.8EPSS 0.6%
- CVE-2026-86426: LibreNMS REST API authentication bypass via type coercioncriticalCVSS 9.8EPSS 3.9%
- CVE-2026-84194: LibreNMS OS command injection in libvirt discoveryinfoCVSS 8.6EPSS 1.5%
- CVE-2026-84193: LibreNMS stored cross-site scripting in SNMP datainfoCVSS 5.8EPSS 0.4%
- CVE-2026-84192: LibreNMS stored cross-site scripting in legacy PHP templateshighCVSS 7.1EPSS 0.3%
- CVE-2026-84191: LibreNMS stored XSS in VRF display pagesmediumCVSS 6.1EPSS 0.3%
- CVE-2026-84190: LibreNMS AboutController remote code execution in snmpget configurationhighCVSS 7.2EPSS 0.9%
- CVE-2026-84189: LibreNMS stored XSS in Oxidized integrationhighCVSS 8.1EPSS 0.4%
- CVE-2026-84188: LibreNMS stored cross-site scripting in graph description settingsmediumCVSS 4.8EPSS 0.3%
- CVE-2026-55182: LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to…highCVSS 8.6EPSS 1.6%
- CVE-2026-45694: LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is…mediumCVSS 5.4EPSS 0.2%
- LibreNMS stored XSS via SNMP/syslog data in legacy templateshighCVSS 7.1
- CVE-2020-15878: LibreNMS SQL injection in ajax_table.phphighCVSS 8.8EPSS 0.5%
- CVE-2020-15876: LibreNMS SQL injection in ajax_table.php sort parameterhighCVSS 8.8EPSS 0.3%
- CVE-2020-15874: LibreNMS command injection in graph.php APIhighCVSS 8.8EPSS 1.1%
- CVE-2026-80214: LibreNMS command injection in Virtualization Discovery moduleinfoCVSS 8.8EPSS 0.5%
- LibreNMS stored XSS in device showconfig via Oxidized APIhighCVSS 8.1
- LibreNMS stored XSS in graph description settingsmediumCVSS 4.8
- LibreNMS remote code execution via AboutControllermediumCVSS 6.4
- CVE-2024-51092: LibreNMS authenticated OS command injection in AboutControllercriticalCVSS 9.1
- LibreNMS remote code execution in Binary Locations confighighCVSS 8.5
- CVE-2026-6204: LibreNMS remote code execution in Binary Locations confighighCVSS 7.2
- CVE-2026-2728: LibreNMS authenticated XSS in showconfig pagemediumCVSS 4.8EPSS 0.0%
Most severe Librenms vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-86426: LibreNMS REST API authentication bypass via type coercioncriticalCVSS 9.8EPSS 3.9%
- CVE-2024-51092: LibreNMS authenticated OS command injection in AboutControllercriticalCVSS 9.1
- CVE-2020-15874: LibreNMS command injection in graph.php APIhighCVSS 8.8EPSS 1.1%
- CVE-2026-86427: LibreNMS argument injection in graph_title parameterhighCVSS 8.8EPSS 0.6%
- CVE-2020-15878: LibreNMS SQL injection in ajax_table.phphighCVSS 8.8EPSS 0.5%
- CVE-2020-15876: LibreNMS SQL injection in ajax_table.php sort parameterhighCVSS 8.8EPSS 0.3%
- CVE-2026-55182: LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to…highCVSS 8.6EPSS 1.6%
- LibreNMS remote code execution in Binary Locations confighighCVSS 8.5
- CVE-2026-84189: LibreNMS stored XSS in Oxidized integrationhighCVSS 8.1EPSS 0.4%
- LibreNMS stored XSS in device showconfig via Oxidized APIhighCVSS 8.1
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 3 | 0 | |
| 24 Aug 2026 | 7 | 0 | |
| 31 Aug 2026 | 7 | 0 | |
| 7 Sep 2026 | 3 | 1 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/librenms.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Librenms vulnerabilities", https://junglewise.ai/threats/technologies/librenms, 26 September 2026.