We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scripting (XSS) Vulnerability in the `group name` parameter of the `http://localhost/poller/groups` form. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users. LibreNMS v25.5.0 contains a patch for the issue.
Reserved 2025-05-14 | Published 2025-05-17 | Updated 2025-05-19 | Assigner GitHub_MCWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
github.com/...brenms/security/advisories/GHSA-hxw5-9cc5-cmw5
github.com/librenms/librenms/pull/17603
github.com/...ommit/88fe1a7abdb500d9a2d4c45f9872df54c9ff8062
github.com/...lob/25.4.0/includes/html/pages/addhost.inc.php
Support options