XSS Vulnerability in GLPI IT Management Software
CVE-2026-25932
7.2HIGH
What is CVE-2026-25932?
GLPI, a popular free asset and IT management software, contains a vulnerability that allows authenticated technician users to store malicious XSS payloads in supplier fields. This flaw affects all versions from 0.60 up to, but not including, 10.0.24. It is crucial for users to upgrade to the latest version to mitigate the risk of exploitation and ensure the security of their IT environment.
Affected Version(s)
glpi >= 0.60, < 10.0.24
