CVE-2026-26027

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*

History

07 Apr 2026, 16:02

Type Values Removed Values Added
References () https://github.com/glpi-project/glpi/security/advisories/GHSA-chch-wcm9-f9cp - () https://github.com/glpi-project/glpi/security/advisories/GHSA-chch-wcm9-f9cp - Vendor Advisory
First Time Glpi-project
Glpi-project glpi
CPE cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*

06 Apr 2026, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-06 15:17

Updated : 2026-04-07 16:02


NVD link : CVE-2026-26027

Mitre link : CVE-2026-26027

CVE.ORG link : CVE-2026-26027


JSON object : View

Products Affected

glpi-project

  • glpi
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-116

Improper Encoding or Escaping of Output

CWE-306

Missing Authentication for Critical Function