← Database

CVE-2026-84188

MEDIUM CVSS: 4.8 Published: 2026-09-01 Modified: 2026-09-01

Description

LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr. configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrator can store a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type. The issue is fixed in version 26.7.0.

Affected Platforms

Unknown

Weakness Type

CWE-79

References