Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15590 | LibreNMS stored Cross-site Scripting vulnerability in poller group name |
Github GHSA |
GHSA-hxw5-9cc5-cmw5 | LibreNMS stored Cross-site Scripting vulnerability in poller group name |
Wed, 28 May 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Librenms
Librenms librenms |
|
| CPEs | cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Librenms
Librenms librenms |
|
| Metrics |
cvssV3_1
|
Mon, 19 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 17 May 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scripting (XSS) Vulnerability in the `group name` parameter of the `http://localhost/poller/groups` form. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users. LibreNMS v25.5.0 contains a patch for the issue. | |
| Title | LibreNMS stored Cross-site Scripting vulnerability in poller group name | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-19T20:17:46.155Z
Reserved: 2025-05-14T10:32:43.529Z
Link: CVE-2025-47931
Updated: 2025-05-19T20:17:40.464Z
Status : Analyzed
Published: 2025-05-17T16:15:19.253
Modified: 2025-05-28T13:19:14.460
Link: CVE-2025-47931
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA