XSS Vulnerability in GLPI IT Management Software
CVE-2026-25932

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
6 April 2026

What is CVE-2026-25932?

GLPI, a popular free asset and IT management software, contains a vulnerability that allows authenticated technician users to store malicious XSS payloads in supplier fields. This flaw affects all versions from 0.60 up to, but not including, 10.0.24. It is crucial for users to upgrade to the latest version to mitigate the risk of exploitation and ensure the security of their IT environment.

Affected Version(s)

glpi >= 0.60, < 10.0.24

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.