PT-2026-56824 · Glpi · Tag Plugin

·

CVE-2026-53987

·

Published

2026-07-09

·

Updated

2026-07-20

CVSS v4.0

7.3

High

VectorAV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Tag plugin for GLPI 11 versions prior to 2.14.4
Description Stored cross-site scripting occurs because the software stores tag names without HTML sanitization and renders them into the Kanban badge markup via the preKanbanContent() function without output escaping. An authenticated user with TAG MANAGEMENT create or update rights can set a tag name containing HTML, which then executes in the browser of any user who opens the Kanban view of a ticket, problem, change, or project associated with that tag.
Recommendations Update Tag plugin for GLPI 11 to version 2.14.4 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53987
GHSA-6RPJ-89C7-X2MH

Affected Products

Tag Plugin