Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-84192

HIGH NVD
CVSS Score 7.1
Severity HIGH
Published Sep 01, 2026
Vendor unknown

Description

LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls a monitored network device can inject arbitrary JavaScript through SNMP interface descriptions or syslog program fields that executes when authenticated users view affected pages.

References