MEDIUM 4.8 NVD
CVE-2026-84188
LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim
LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrator can store a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type. The issue is fixed in version 26.7.0.
References
- https://github.com/librenms/librenms/security/advisories/GHSA-7cj5-v4pp-v632
- https://www.vulncheck.com/advisories/librenms-before-26.7.0-stored-xss-via-graph-descr-set
This medium severity vulnerability with a CVSS score of 4.8 was published on 2026-09-01 via NVD.
vulnfeed aggregates 11474 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.