CVE-2026-53610High· 7.5▾ TwilightGLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without sufficient output encoding. A user who opens the crafted URL …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without sufficient output encoding. A user who opens the crafted URL triggers reflected cross-site scripting in the dashboard. This issue is fixed in version 11.0.8.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-49469Medium· 4.6GLPI is a free asset and IT management software package
CVE-2026-45801Medium· 5.3GLPI is a free asset and IT management software package
CVE-2026-53628Medium· 5.9GLPI is a free asset and IT management software package
CVE-2026-49470High· 7.7GLPI is a free asset and IT management software package
CVE-2026-55214High· 8.5GLPI is a free asset and IT management software package
CVE-2026-48482Critical· 9.4GLPI is a free asset and IT management software package