Reflected Cross-Site Scripting Vulnerability in GLPI IT Management Software
CVE-2026-53610
7.5HIGH
What is CVE-2026-53610?
GLPI, a popular free asset and IT management software, has a vulnerability that affects versions 11.0.0 through 11.0.8. An attacker can exploit this flaw by crafting a malicious URL for the dashboard that embeds attacker-controlled markup. If a user accesses the manipulated URL, it results in reflected cross-site scripting (XSS) within the dashboard interface. This vulnerability allows potential attackers to execute arbitrary scripts in the context of the user’s session. GLPI has resolved this security flaw in version 11.0.8, and it is strongly recommended that users upgrade to mitigate risks associated with this vulnerability.
Affected Version(s)
glpi >= 11.0.0, < 11.0.8
