CVE-2025-26626

The GLPI Inventory Plugin handles various types of tasks for GLPI agents for the GLPI asset and IT management software package. Versions prior to 1.5.0 are vulnerable to reflective cross-site scripting, which may lead to executing javascript code. Version 1.5.0 fixes the issue.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) El complemento GLPI Inventory gestiona diversos tipos de tareas para los agentes de GLPI del paquete de software de gestión de activos y TI de GLPI. Las versiones anteriores a la 1.5.0 son vulnerables a cross-site scripting reflejado, lo que puede provocar la ejecución de código JavaScript. La versión 1.5.0 soluciona el problema.

14 Mar 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-14 13:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-26626

Mitre link : CVE-2025-26626

CVE.ORG link : CVE-2025-26626


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')