GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 06 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6. | |
| Title | GLPI has an Unauthenticated Stored XSS via inventory | |
| Weaknesses | CWE-116 CWE-306 CWE-79 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-06T14:51:39.422Z
Reserved: 2026-02-09T21:36:29.555Z
Link: CVE-2026-26027
Updated: 2026-04-06T14:51:34.878Z
Status : Received
Published: 2026-04-06T15:17:07.243
Modified: 2026-04-06T15:17:07.243
Link: CVE-2026-26027
No data.
OpenCVE Enrichment
No data.