References https://avd.aliyun.com/detail?id=AVD-2024-47525 https://www.juniper.net/us/en/threatlabs/ips-signatures/detail.HTTP:XSS:LIBRENMS-NOTIF-TITLE.html https://projectblack.io/blog/librenms-authenticated-rce-and-xss/ https://github.com/librenms/librenms/security/advisories/GHSA-vxq6-8cwm-wj99 https://www.knowsafe.com/ti/info/0/999766 https://app.opencve.io/cve/?page=3&vendor=librenms https://zone.ci/aliyun/ali_nvd/384413.html https://advisories.gitlab.com/pkg/composer/librenms/librenms/CVE-2024-50350/ https://community.librenms.org/t/vulnerability-report-cross-site-scripting-xss-in-the-api-access-page/15431 https://support.trellix.com/s/article/KB96648 https://autoupdate.ngfw.forcepoint.com/download/dynup/sgpkg-1983-SUMMARY.html https://nvd.nist.gov/vuln/detail/CVE-2024-47525 https://security.snyk.io/vuln/SNYK-PHP-LIBRENMSLIBRENMS-5905994
Related VulnerabilitiesPoCCVE-2026-86426: LibreNMS <= 26.7.0 - Unauthenticated API AccessDozzle /api/notifications/test-webhook 服务器端请求伪造漏洞(CVE-2026-45298)Ech0 title接口存在服务端请求伪造漏洞(CVE-2026-35037)Ech0 /api/website/title 服务器端请求伪造漏洞(CVE-2026-35037)孚盟云 getTitle SQL注入漏洞上海物创信息科技有限公司仓储系统和物流管理系统ligerUI_Export.ashx Title参数存在SQL注入漏洞快普M6 /WebService/wsAutoComplete.asmx/GetAccountTitleList SQL 注入漏洞PoC快普整合管理平台 GetAccountTitleList SQL注入漏洞快普M6 GetAccountTitleList 存在SQL注入漏洞PoCCVE-2022-0784: WordPress Title Experiments Free <9.0.1 - SQL InjectionPoCCVE-2022-2535: SearchWP Live Ajax Search < 1.6.2 - Unauthenticated Arbitrary Post Title DisclosurePoCsecurity-notification-disabled: Security Center Notifications - Disabled