We found results for “”
CVE-2025-62365
Good to know:
Date: October 13, 2025
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in "report_this" function in "librenms/includes/functions.php". The "report_this" function had improper filtering ("htmlentities" function was incorrectly use in a href environment), which caused the "project_issues" parameter to trigger an XSS vulnerability. This vulnerability is fixed in 25.7.0.
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | LOW |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


