LibreNMS is a network monitoring and management platform that, despite a single-product focus, occupies a prominent position in enterprise and service-provider infrastructure due to its open-source adoption and deployment breadth. Its vulnerability profile centers on web-application and input-handling weaknesses: cross-site scripting, SQL injection, OS command injection, output-encoding flaws, and path traversal, reflecting the risks inherent to a data-collection and visualization system that processes user input and interacts with monitored network devices. Vulnerabilities affecting the vendor span a meaningful range of severity outcomes, with a notable share reaching serious levels; the recurring weakness classes underscore the importance of robust input validation and output sanitization in a monitoring application that handles untrusted user queries and device responses. Defenders deploying LibreNMS should prioritize access controls and network segmentation, treat the monitoring platform as a sensitive infrastructure component, and maintain current patches given the exposure surface created by web-application and command-execution pathways. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Librenms over time
Signals from CVEs in this vendor scope (104 CVEs).
104 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20434CRITICAL LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and | Apr 24, 2019 | 9.8 | 85 | NO | YES |
CVE-2019-10669HIGH An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where user supplied parameters are filt | Sep 9, 2019 | 7.2 | 83 | NO | YES |
CVE-2022-4067MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. | Nov 20, 2022 | 5.4 | 71 | NO | NO |
CVE-2022-3562MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. | Nov 20, 2022 | 5.4 | 71 | NO | NO |
CVE-2022-4069MEDIUM Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0. | Nov 20, 2022 | 4.8 | 69 | NO | NO |
CVE-2023-4347MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0. | Aug 15, 2023 | 5.4 | 53 | NO | NO |
CVE-2024-49754MEDIUM LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the API-Access page allows authenticated users to i | Nov 15, 2024 | 5.4 | 52 | NO | NO |
CVE-2024-51092CRITICAL LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.php's update(), and | May 8, 2026 | 9.1 | 48 | NO | YES |
CVE-2022-4068MEDIUM A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin | Nov 20, 2022 | 5.4 | 37 | NO | NO |
CVE-2026-26988CRITICAL LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in the ajax_table.php endpoint. The | Feb 20, 2026 | 9.1 | 36 | NO | NO |
Signals from CVEs in this vendor scope (104 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Librenms.
Media articles that mention a CVE ID that affects a product developed by Librenms — matched by CVE ID, not by vendor name.