CVE-2025-27514: GLPI is susceptible to Stored XSS attack through project's kanban
Published Jul 29, 2025
·Updated
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a technician can use a malicious payload to trigger a stored XSS on the project's kanban. This is fixed in version 10.0.19.
Affected Software
2 affected components
GLPI GLPI>=9.5.0<=10.0.18
GLPI-PROJECT GLPI>=9.5.0<10.0.19
Remediation
Event History
Jul 29, 2025
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27514?
CVE-2025-27514 is categorized as a moderate severity vulnerability due to its potential for stored XSS attacks.
2
How do I fix CVE-2025-27514?
To mitigate CVE-2025-27514, upgrade your GLPI installation to version 10.0.19 or later.
3
What versions are affected by CVE-2025-27514?
CVE-2025-27514 affects GLPI versions from 9.5.0 to 10.0.18.
4
What type of vulnerability is CVE-2025-27514?
CVE-2025-27514 is a stored Cross-Site Scripting (XSS) vulnerability.
5
Who can exploit CVE-2025-27514?
CVE-2025-27514 can be exploited by any technician with access to the project's kanban in the affected GLPI versions.