Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-53610: GLPI dashboards can run malicious code via crafted link
CVE-2026-53610 · published 2 days ago
Summary
Versions of GLPI from 11.0.0 through 11.0.8 allow a specially‑made web address to display content that the attacker supplies. If a user clicks that link, the malicious content can execute in their browser, potentially stealing information or performing actions as that user. Upgrade to GLPI 11.0.8 or later to stop this behavior.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| glpi-project | glpi | >= 11.0.0, < 11.0.8 |
Original advisory text
GLPI: Reflected XSS in dashboards
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without sufficient output encoding. A user who opens the crafted URL triggers reflected cross-site scripting in the dashboard. This issue is fixed in version 11.0.8.
References
- https://github.com/glpi-project/glpi/commit/9b17a3b2b91070cf197dedae3286322a41c4... Patch
- https://github.com/glpi-project/glpi/releases/tag/11.0.8 URL
- https://github.com/glpi-project/glpi/security/advisories/GHSA-76v9-ch69-g67r Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53610... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-53610 Vendor Advisory
Severity
9.9
Critical
CVSS 4.0: 7.5 (NVD)
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published25 Sep 2026
Updated27 Sep 2026
First seen25 Sep 2026
Track software like this
Free during beta