CVE-2025-62412
16.10.2025, 18:15
LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules page is not properly sanitized, and can be used to inject HTML code. This vulnerability is fixed in 25.10.0.
| Vendor | Product | Version |
|---|---|---|
| librenms | librenms | 25.8.0 ≤ 𝑥 < 25.10.0 |
𝑥
= Vulnerable software versions