{"schema_version":1,"title":"Librenms vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 24 vulnerabilities in Librenms: 0 in the last 7 days and 20 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2020-15875, was published on 13 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/librenms","json_url":"https://junglewise.ai/threats/vendors/librenms.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/librenms","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":12,"all_time":24,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":10,"last_90_days":20,"last_365_days":24},"latest":[{"cve":"CVE-2020-15875","cvss":5,"epss":0.0034,"slug":"cve-2020-15875-librenms-sql-injection-in-ajax-table-php","title":"LibreNMS SQL injection in ajax_table.php","severity":"medium","exploited":false,"published_at":"2026-09-13T19:16:51.627+00:00","url":"https://junglewise.ai/threats/cve-2020-15875-librenms-sql-injection-in-ajax-table-php"},{"cve":"CVE-2026-86427","cvss":8.8,"epss":0.0061,"slug":"cve-2026-86427-librenms-argument-injection-in-graph-title-parameter","title":"LibreNMS argument injection in graph_title parameter","severity":"high","exploited":false,"published_at":"2026-09-07T13:20:41.87+00:00","url":"https://junglewise.ai/threats/cve-2026-86427-librenms-argument-injection-in-graph-title-parameter"},{"cve":"CVE-2026-86426","cvss":9.8,"epss":0.0387,"slug":"cve-2026-86426-librenms-rest-api-authentication-bypass-via-type-coercion","title":"LibreNMS REST API authentication bypass via type coercion","severity":"critical","exploited":false,"published_at":"2026-09-07T13:20:41.69+00:00","url":"https://junglewise.ai/threats/cve-2026-86426-librenms-rest-api-authentication-bypass-via-type-coercion"},{"cve":"CVE-2026-84194","cvss":8.6,"epss":0.0153,"slug":"cve-2026-84194-librenms-os-command-injection-in-libvirt-discovery","title":"LibreNMS OS command injection in libvirt discovery","severity":"info","exploited":false,"published_at":"2026-09-01T12:17:49+00:00","url":"https://junglewise.ai/threats/cve-2026-84194-librenms-os-command-injection-in-libvirt-discovery"},{"cve":"CVE-2026-84193","cvss":5.8,"epss":0.0035,"slug":"cve-2026-84193-librenms-stored-cross-site-scripting-in-snmp-data","title":"LibreNMS stored cross-site scripting in SNMP data","severity":"info","exploited":false,"published_at":"2026-09-01T12:17:48.867+00:00","url":"https://junglewise.ai/threats/cve-2026-84193-librenms-stored-cross-site-scripting-in-snmp-data"},{"cve":"CVE-2026-84192","cvss":7.1,"epss":0.0033,"slug":"cve-2026-84192-librenms-stored-cross-site-scripting-in-legacy-php-templates","title":"LibreNMS stored cross-site scripting in legacy PHP templates","severity":"high","exploited":false,"published_at":"2026-09-01T12:17:48.723+00:00","url":"https://junglewise.ai/threats/cve-2026-84192-librenms-stored-cross-site-scripting-in-legacy-php-templates"},{"cve":"CVE-2026-84191","cvss":6.1,"epss":0.0026,"slug":"cve-2026-84191-librenms-stored-xss-in-vrf-display-pages","title":"LibreNMS stored XSS in VRF display pages","severity":"medium","exploited":false,"published_at":"2026-09-01T12:17:48.587+00:00","url":"https://junglewise.ai/threats/cve-2026-84191-librenms-stored-xss-in-vrf-display-pages"},{"cve":"CVE-2026-84190","cvss":7.2,"epss":0.0086,"slug":"cve-2026-84190-librenms-aboutcontroller-remote-code-execution-in-snmpget","title":"LibreNMS AboutController remote code execution in snmpget configuration","severity":"high","exploited":false,"published_at":"2026-09-01T12:17:48.45+00:00","url":"https://junglewise.ai/threats/cve-2026-84190-librenms-aboutcontroller-remote-code-execution-in-snmpget"},{"cve":"CVE-2026-84189","cvss":8.1,"epss":0.0038,"slug":"cve-2026-84189-librenms-stored-xss-in-oxidized-integration","title":"LibreNMS stored XSS in Oxidized integration","severity":"high","exploited":false,"published_at":"2026-09-01T12:17:48.287+00:00","url":"https://junglewise.ai/threats/cve-2026-84189-librenms-stored-xss-in-oxidized-integration"},{"cve":"CVE-2026-84188","cvss":4.8,"epss":0.0025,"slug":"cve-2026-84188-librenms-stored-cross-site-scripting-in-graph-description","title":"LibreNMS stored cross-site scripting in graph description settings","severity":"medium","exploited":false,"published_at":"2026-09-01T12:17:48.143+00:00","url":"https://junglewise.ai/threats/cve-2026-84188-librenms-stored-cross-site-scripting-in-graph-description"},{"cve":"CVE-2026-55182","cvss":4,"epss":0.0161,"slug":"cve-2026-55182-librenms-remote-code-execution-in-signal-alert-transport","title":"LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection","severity":"high","exploited":false,"published_at":"2026-08-26T22:16:24.95+00:00","url":"https://junglewise.ai/threats/cve-2026-55182-librenms-remote-code-execution-in-signal-alert-transport"},{"cve":"CVE-2026-45694","cvss":5.4,"epss":0.0024,"slug":"cve-2026-45694-librenms-reflected-xss-in-proxmox-application-component","title":"LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cro","severity":"medium","exploited":false,"published_at":"2026-08-26T22:16:24.793+00:00","url":"https://junglewise.ai/threats/cve-2026-45694-librenms-reflected-xss-in-proxmox-application-component"},{"cvss":7.1,"slug":"librenms-stored-xss-via-snmp-syslog-data-in-legacy-templates-a27e8a90","title":"LibreNMS stored XSS via SNMP/syslog data in legacy templates","severity":"high","exploited":false,"published_at":"2026-08-26T18:05:46+00:00","url":"https://junglewise.ai/threats/librenms-stored-xss-via-snmp-syslog-data-in-legacy-templates-a27e8a90"},{"cve":"CVE-2020-15878","cvss":8.8,"epss":0.0046,"slug":"cve-2020-15878-librenms-sql-injection-in-ajax-table-php","title":"LibreNMS SQL injection in ajax_table.php","severity":"high","exploited":false,"published_at":"2026-08-26T17:16:45.197+00:00","url":"https://junglewise.ai/threats/cve-2020-15878-librenms-sql-injection-in-ajax-table-php"},{"cve":"CVE-2020-15876","cvss":8.8,"epss":0.0034,"slug":"cve-2020-15876-librenms-sql-injection-in-ajax-table-php-sort-parameter","title":"LibreNMS SQL injection in ajax_table.php sort parameter","severity":"high","exploited":false,"published_at":"2026-08-26T17:16:45.08+00:00","url":"https://junglewise.ai/threats/cve-2020-15876-librenms-sql-injection-in-ajax-table-php-sort-parameter"},{"cve":"CVE-2020-15874","cvss":8.8,"epss":0.0112,"slug":"cve-2020-15874-librenms-command-injection-in-graph-php-api","title":"LibreNMS command injection in graph.php API","severity":"high","exploited":false,"published_at":"2026-08-26T17:16:44.097+00:00","url":"https://junglewise.ai/threats/cve-2020-15874-librenms-command-injection-in-graph-php-api"},{"cve":"CVE-2026-80214","cvss":8.8,"epss":0.0054,"slug":"cve-2026-80214-librenms-command-injection-in-virtualization-discovery-module","title":"LibreNMS command injection in Virtualization Discovery module","severity":"info","exploited":false,"published_at":"2026-08-26T05:18:28.127+00:00","url":"https://junglewise.ai/threats/cve-2026-80214-librenms-command-injection-in-virtualization-discovery-module"},{"cvss":8.1,"slug":"librenms-stored-xss-in-device-showconfig-via-oxidized-api-e20d3cc8","title":"LibreNMS stored XSS in device showconfig via Oxidized API","severity":"high","exploited":false,"published_at":"2026-08-18T21:17:23+00:00","url":"https://junglewise.ai/threats/librenms-stored-xss-in-device-showconfig-via-oxidized-api-e20d3cc8"},{"cvss":4.8,"slug":"librenms-stored-xss-in-graph-description-settings-ffdfb5dd","title":"LibreNMS stored XSS in graph description settings","severity":"medium","exploited":false,"published_at":"2026-08-18T21:17:20+00:00","url":"https://junglewise.ai/threats/librenms-stored-xss-in-graph-description-settings-ffdfb5dd"},{"cvss":6.4,"slug":"librenms-remote-code-execution-via-aboutcontroller-d7e2e3b0","title":"LibreNMS remote code execution via AboutController","severity":"medium","exploited":false,"published_at":"2026-08-18T21:17:11+00:00","url":"https://junglewise.ai/threats/librenms-remote-code-execution-via-aboutcontroller-d7e2e3b0"},{"cve":"CVE-2024-51092","cvss":9.1,"epss":0.0718,"slug":"cve-2024-51092-librenms-authenticated-os-command-injection-in-aboutcontroller","title":"LibreNMS OS command injection in AboutController and SettingsController","severity":"critical","exploited":false,"published_at":"2026-05-08T06:16:10.09+00:00","url":"https://junglewise.ai/threats/cve-2024-51092-librenms-authenticated-os-command-injection-in-aboutcontroller"},{"cvss":8.5,"slug":"librenms-remote-code-execution-in-binary-locations-config-37285679","title":"LibreNMS remote code execution in Binary Locations config","severity":"high","exploited":false,"published_at":"2026-04-13T12:31:15+00:00","url":"https://junglewise.ai/threats/librenms-remote-code-execution-in-binary-locations-config-37285679"},{"cve":"CVE-2026-6204","cvss":7.2,"epss":0.0093,"slug":"cve-2026-6204-librenms-remote-code-execution-in-binary-locations-config","title":"LibreNMS remote code execution in Binary Locations config","severity":"high","exploited":false,"published_at":"2026-04-13T11:16:06.243+00:00","url":"https://junglewise.ai/threats/cve-2026-6204-librenms-remote-code-execution-in-binary-locations-config"},{"cve":"CVE-2026-2728","cvss":4.8,"epss":0.0025,"slug":"cve-2026-2728-librenms-authenticated-xss-in-showconfig-page","title":"LibreNMS authenticated XSS in showconfig page","severity":"medium","exploited":false,"published_at":"2026-04-13T11:16:05.407+00:00","url":"https://junglewise.ai/threats/cve-2026-2728-librenms-authenticated-xss-in-showconfig-page"}],"vendor":{"hub":true,"name":"Librenms","slug":"librenms","homepage":"https://www.librenms.org/","description":"LibreNMS is a community-driven project providing a fully featured network monitoring system.","url":"https://junglewise.ai/threats/vendors/librenms"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-09-07","critical":1,"exploited":0,"vulnerabilities":3},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-86426","cvss":9.8,"epss":0.0387,"slug":"cve-2026-86426-librenms-rest-api-authentication-bypass-via-type-coercion","title":"LibreNMS REST API authentication bypass via type coercion","severity":"critical","exploited":false,"published_at":"2026-09-07T13:20:41.69+00:00","url":"https://junglewise.ai/threats/cve-2026-86426-librenms-rest-api-authentication-bypass-via-type-coercion"},{"cve":"CVE-2024-51092","cvss":9.1,"epss":0.0718,"slug":"cve-2024-51092-librenms-authenticated-os-command-injection-in-aboutcontroller","title":"LibreNMS OS command injection in AboutController and SettingsController","severity":"critical","exploited":false,"published_at":"2026-05-08T06:16:10.09+00:00","url":"https://junglewise.ai/threats/cve-2024-51092-librenms-authenticated-os-command-injection-in-aboutcontroller"},{"cve":"CVE-2020-15874","cvss":8.8,"epss":0.0112,"slug":"cve-2020-15874-librenms-command-injection-in-graph-php-api","title":"LibreNMS command injection in graph.php API","severity":"high","exploited":false,"published_at":"2026-08-26T17:16:44.097+00:00","url":"https://junglewise.ai/threats/cve-2020-15874-librenms-command-injection-in-graph-php-api"},{"cve":"CVE-2026-86427","cvss":8.8,"epss":0.0061,"slug":"cve-2026-86427-librenms-argument-injection-in-graph-title-parameter","title":"LibreNMS argument injection in graph_title parameter","severity":"high","exploited":false,"published_at":"2026-09-07T13:20:41.87+00:00","url":"https://junglewise.ai/threats/cve-2026-86427-librenms-argument-injection-in-graph-title-parameter"},{"cve":"CVE-2020-15878","cvss":8.8,"epss":0.0046,"slug":"cve-2020-15878-librenms-sql-injection-in-ajax-table-php","title":"LibreNMS SQL injection in ajax_table.php","severity":"high","exploited":false,"published_at":"2026-08-26T17:16:45.197+00:00","url":"https://junglewise.ai/threats/cve-2020-15878-librenms-sql-injection-in-ajax-table-php"},{"cve":"CVE-2020-15876","cvss":8.8,"epss":0.0034,"slug":"cve-2020-15876-librenms-sql-injection-in-ajax-table-php-sort-parameter","title":"LibreNMS SQL injection in ajax_table.php sort parameter","severity":"high","exploited":false,"published_at":"2026-08-26T17:16:45.08+00:00","url":"https://junglewise.ai/threats/cve-2020-15876-librenms-sql-injection-in-ajax-table-php-sort-parameter"},{"cvss":8.5,"slug":"librenms-remote-code-execution-in-binary-locations-config-37285679","title":"LibreNMS remote code execution in Binary Locations config","severity":"high","exploited":false,"published_at":"2026-04-13T12:31:15+00:00","url":"https://junglewise.ai/threats/librenms-remote-code-execution-in-binary-locations-config-37285679"},{"cve":"CVE-2026-84189","cvss":8.1,"epss":0.0038,"slug":"cve-2026-84189-librenms-stored-xss-in-oxidized-integration","title":"LibreNMS stored XSS in Oxidized integration","severity":"high","exploited":false,"published_at":"2026-09-01T12:17:48.287+00:00","url":"https://junglewise.ai/threats/cve-2026-84189-librenms-stored-xss-in-oxidized-integration"},{"cvss":8.1,"slug":"librenms-stored-xss-in-device-showconfig-via-oxidized-api-e20d3cc8","title":"LibreNMS stored XSS in device showconfig via Oxidized API","severity":"high","exploited":false,"published_at":"2026-08-18T21:17:23+00:00","url":"https://junglewise.ai/threats/librenms-stored-xss-in-device-showconfig-via-oxidized-api-e20d3cc8"},{"cve":"CVE-2026-6204","cvss":7.2,"epss":0.0093,"slug":"cve-2026-6204-librenms-remote-code-execution-in-binary-locations-config","title":"LibreNMS remote code execution in Binary Locations config","severity":"high","exploited":false,"published_at":"2026-04-13T11:16:06.243+00:00","url":"https://junglewise.ai/threats/cve-2026-6204-librenms-remote-code-execution-in-binary-locations-config"}],"generated_at":"2026-09-26T20:07:00.238639+00:00","technologies":[{"name":"Librenms","slug":"librenms","vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/librenms"}]}