Vulnerabilities > Librenms

DATE CVE VULNERABILITY TITLE RISK
2022-11-20 CVE-2022-3561 Cross-site Scripting vulnerability in Librenms
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.
network
low complexity
librenms CWE-79
6.1
2022-11-20 CVE-2022-3562 Cross-site Scripting vulnerability in Librenms
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
network
low complexity
librenms CWE-79
5.4
2022-11-20 CVE-2022-4067 Cross-site Scripting vulnerability in Librenms
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
network
low complexity
librenms CWE-79
5.4
2022-11-20 CVE-2022-4068 Cross-site Scripting vulnerability in Librenms
A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session.
network
low complexity
librenms CWE-79
5.4
2022-11-20 CVE-2022-4069 Cross-site Scripting vulnerability in Librenms
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.
network
low complexity
librenms CWE-79
4.8
2022-11-20 CVE-2022-4070 Insufficient Session Expiration vulnerability in Librenms
Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.
network
low complexity
librenms CWE-613
critical
9.8
2022-09-17 CVE-2022-3231 Cross-site Scripting vulnerability in Librenms
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0.
network
low complexity
librenms CWE-79
5.4
2022-08-30 CVE-2022-36745 Cross-site Scripting vulnerability in Librenms 22.6.0
LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php.
network
low complexity
librenms CWE-79
6.1
2022-08-30 CVE-2022-36746 Cross-site Scripting vulnerability in Librenms 22.6.0
LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php.
network
low complexity
librenms CWE-79
6.1
2022-06-02 CVE-2022-29711 Cross-site Scripting vulnerability in Librenms 22.3.0
LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogController.php.
network
low complexity
librenms CWE-79
6.1