LibreNMS versions <= 26.4.0 contain a stored cross-site...
Moderate severity
Unreviewed
Published
Sep 1, 2026
to the GitHub Advisory Database
•
Updated Sep 1, 2026
Description
Published by the National Vulnerability Database
Sep 1, 2026
Published to the GitHub Advisory Database
Sep 1, 2026
Last updated
Sep 1, 2026
LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr. configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrator can store a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type. The issue is fixed in version 26.7.0.
References