Vulnerability Details CVE-2025-62412
LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules page is not properly sanitized, and can be used to inject HTML code. This vulnerability is fixed in 25.10.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.1%
CVSS Severity
CVSS v3 Score 3.8
Products affected by CVE-2025-62412
-
cpe:2.3:a:librenms:librenms:25.8.0
-
cpe:2.3:a:librenms:librenms:25.9.0
-
cpe:2.3:a:librenms:librenms:25.9.1