LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in `report_this` function in `librenms/includes/functions.php`. The `report_this` function had improper filtering (`htmlentities` function was incorrectly use in a href environment), which caused the `project_issues` parameter to trigger an XSS vulnerability. This vulnerability is fixed in 25.7.0.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-86rg-8hc8-v82p LibreNMS is vulnerable to Reflected-XSS in `report_this` function
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 14 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Oct 2025 21:45:00 +0000

Type Values Removed Values Added
Description LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in `report_this` function in `librenms/includes/functions.php`. The `report_this` function had improper filtering (`htmlentities` function was incorrectly use in a href environment), which caused the `project_issues` parameter to trigger an XSS vulnerability. This vulnerability is fixed in 25.7.0.
Title LibreNMS vulnerable to Reflected-XSS in `report_this` function
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-10-14T15:16:41.306Z

Reserved: 2025-10-10T14:22:48.203Z

Link: CVE-2025-62365

cve-icon Vulnrichment

Updated: 2025-10-14T15:16:38.150Z

cve-icon NVD

Status : Received

Published: 2025-10-13T22:15:34.080

Modified: 2025-10-13T22:15:34.080

Link: CVE-2025-62365

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.