GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Glpi-project
Glpi-project glpi |
|
| Vendors & Products |
Glpi-project
Glpi-project glpi |
Mon, 06 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6. | |
| Title | GLPI has an Unauthenticated Stored XSS via inventory | |
| Weaknesses | CWE-116 CWE-306 CWE-79 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T03:55:40.983Z
Reserved: 2026-02-09T21:36:29.555Z
Link: CVE-2026-26027
Updated: 2026-04-06T14:51:34.878Z
Status : Undergoing Analysis
Published: 2026-04-06T15:17:07.243
Modified: 2026-04-07T13:20:35.010
Link: CVE-2026-26027
No data.