CVE-2025-62412
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
16/10/2025
Last modified:
23/10/2025
Description
LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules page is not properly sanitized, and can be used to inject HTML code. This vulnerability is fixed in 25.10.0.
Impact
Base Score 3.x
3.80
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* | 25.8.0 (including) | 25.10.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



