Reflected Cross-Site Scripting Vulnerability in GLPI IT Management Software
CVE-2026-53610

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-53610?

GLPI, a popular free asset and IT management software, has a vulnerability that affects versions 11.0.0 through 11.0.8. An attacker can exploit this flaw by crafting a malicious URL for the dashboard that embeds attacker-controlled markup. If a user accesses the manipulated URL, it results in reflected cross-site scripting (XSS) within the dashboard interface. This vulnerability allows potential attackers to execute arbitrary scripts in the context of the user’s session. GLPI has resolved this security flaw in version 11.0.8, and it is strongly recommended that users upgrade to mitigate risks associated with this vulnerability.

Affected Version(s)

glpi >= 11.0.0, < 11.0.8

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.