We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-47931

LibreNMS stored Cross-site Scripting vulnerability in poller group name



Description

LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scripting (XSS) Vulnerability in the `group name` parameter of the `http://localhost/poller/groups` form. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users. LibreNMS v25.5.0 contains a patch for the issue.

Reserved 2025-05-14 | Published 2025-05-17 | Updated 2025-05-19 | Assigner GitHub_M


LOW: 2.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

< 25.5.0
affected

References

github.com/...brenms/security/advisories/GHSA-hxw5-9cc5-cmw5

github.com/librenms/librenms/pull/17603

github.com/...ommit/88fe1a7abdb500d9a2d4c45f9872df54c9ff8062

github.com/...lob/25.4.0/includes/html/pages/addhost.inc.php

cve.org (CVE-2025-47931)

nvd.nist.gov (CVE-2025-47931)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-47931

Support options

Helpdesk Chat, Email, Knowledgebase