PT-2026-99075 · Glpi · Glpi

CVE-2026-55214

·

Published

2026-09-25

·

Updated

2026-09-29

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GLPI versions 11.0.6 through 11.0.7
Description An authenticated technician can store active markup in supplier website fields. This leads to stored cross-site scripting (XSS), where any user viewing the affected item's suppliers list triggers the payload. Cross-site scripting is a technique where malicious scripts are injected into trusted websites.
Recommendations Update to version 11.0.8.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55214
GHSA-8V8P-W8MQ-WQCG

Affected Products

Glpi