icon

We found results for “

CVE-2025-62365

Good to know:

icon
icon

Date: October 13, 2025

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in "report_this" function in "librenms/includes/functions.php". The "report_this" function had improper filtering ("htmlentities" function was incorrectly use in a href environment), which caused the "project_issues" parameter to trigger an XSS vulnerability. This vulnerability is fixed in 25.7.0.

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version librenms/librenms - 25.7.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us