CVE-2025-47931 - CVE House
Back to Database
Status published Low CVE-2025-47931

LibreNMS stored Cross-site Scripting vulnerability in poller group name

Vulnerability Description

LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scripting (XSS) Vulnerability in the `group name` parameter of the `http://localhost/poller/groups` form. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users. LibreNMS v25.5.0 contains a patch for the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-47931

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

librenms
Vulnerable Versions:
< 25.5.0

Timeline

Official Publish: May 17th, 2025
Last Modified: May 19th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)