CVE-2026-53987

The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban badge markup via PluginTagTag::preKanbanContent() without output escaping, resulting in stored cross-site scripting. An authenticated user with TAG MANAGEMENT create or update rights can set a tag name containing HTML, which then executes in the browser of any user who opens the Kanban view of a ticket, problem, change, or project the tag is attached to.
Configurations

No configuration.

History

20 Jul 2026, 18:16

Type Values Removed Values Added
References
  • () https://www.vulncheck.com/advisories/glpi-tag-plugin-stored-cross-site-scripting-in-kanban-badge-rendering -

09 Jul 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-09 17:17

Updated : 2026-07-20 18:16


NVD link : CVE-2026-53987

Mitre link : CVE-2026-53987

CVE.ORG link : CVE-2026-53987


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')