Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-55214: GLPI supplier pages can run malicious code

CVE-2026-55214 · published 2 days ago
Summary

In GLPI versions 11.0.6 through 11.0.8, a logged‑in technician can place hidden code in the supplier information fields. When any user opens the supplier list for that item, the hidden code runs in their web browser, potentially stealing data or taking other actions. Upgrade to GLPI 11.0.8 or later to remove the risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
glpi-project glpi >= 11.0.6, < 11.0.8
Original advisory text
GLPI: Stored XSS in suppliers
GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the stored cross-site scripting payload. This issue is fixed in version 11.0.8.
Severity
9.4 Critical
CVSS 4.0: 8.5 (NVD)
Exploitation
EPSS <1%
Type
CWE-116Improper Encoding or Escaping of Output
Timeline
Published25 Sep 2026
Updated27 Sep 2026
First seen25 Sep 2026
Sources
CVE-2026-55214 · MITRE
Track software like this
Free during beta