Loading market data...
← Back to CVE feed

CVE-2026-26027

HIGH CVSS 7.5 View on NVD ↗

Description

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Published: Apr 06, 2026 15:17 UTC Modified: Apr 06, 2026 15:17 UTC