Glpi · Tag Plugin · CVE-2026-53987
**Name of the Vulnerable Software and Affected Versions**
Tag plugin for GLPI 11 versions prior to 2.14.4
**Description**
Stored cross-site scripting occurs because the software stores tag names without HTML sanitization and renders them into the Kanban badge markup via the `preKanbanContent()` function without output escaping. An authenticated user with TAG MANAGEMENT create or update rights can set a tag name containing HTML, which then executes in the browser of any user who opens the Kanban view of a ticket, problem, change, or project associated with that tag.
**Recommendations**
Update Tag plugin for GLPI 11 to version 2.14.4 or later.