THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7w8c-qgxg-m7jx (high) — LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates

[GHSA] GHSA-7w8c-qgxg-m7jx (high) — LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates

highgithub_advisoriesPublished 2026-08-26

GHSA-7w8c-qgxg-m7jx Severity: high CVE: None

LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates

## Summary

Multiple legacy PHP template files in LibreNMS directly output SNMP-sourced and syslog-sourced data into HTML without escaping. An attacker who controls a monitored network device (via compromised SNMP agent or syslog sender) can inject arbitrary JavaScript that executes when a

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7w8c-qgxg-m7jx