Cross-Site Scripting in GLPI 11.0.6 to 11.0.8 by Authenticated Users
CVE-2026-55214
8.5HIGH
What is CVE-2026-55214?
GLPI, a widely used asset and IT management tool, has a vulnerability affecting versions 11.0.6 to 11.0.8. Authenticated technicians can store malicious scripts in the supplier website fields, which are triggered when any user views the suppliers list for an affected item. This stored cross-site scripting (XSS) issue poses a significant risk, allowing attackers to execute arbitrary scripts in the context of other users. GLPI 11.0.8 addresses this vulnerability, and users are encouraged to upgrade to the latest version to ensure their systems are secure.
Affected Version(s)
glpi >= 11.0.6, < 11.0.8
