LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrator can store a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type. The issue is fixed in version 26.7.0.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-01 12:17
Updated : 2026-09-08 20:18
NVD link : CVE-2026-84188
Mitre link : CVE-2026-84188
CVE.ORG link : CVE-2026-84188
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
