LibreNMS versions prior to 26.3.1 are affected by a stored cross-site scripting (XSS) vulnerability in legacy PHP templates. The vulnerability arises because SNMP-sourced and syslog-sourced data are output without proper escaping. An attacker who controls a monitored network device can inject arbitrary JavaScript payloads through SNMP interface descriptions or syslog program fields. These payloads execute in the browser context of authenticated users who view the affected pages. The attack vector requires the attacker to control a device being monitored by the LibreNMS instance. Exploitation could lead to session hijacking, credential theft, or further lateral movement within the network management environment. Users are strongly advised to upgrade to LibreNMS 26.3.1 or later to remediate the vulnerability. The issue has been disclosed via GitHub Security Advisories and tracked by VulnCheck.