CVE-2025-59935: GLPI Vulnerable to Unauthenticated Stored XSS on the Inventory page
Published Dec 16, 2025
·Updated
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inventory endpoint. Users should upgrade to 10.0.21 to receive a patch.
Affected Software
2 affected components
glpi/glpi>=10.0.0<10.0.21
GLPI-PROJECT GLPI>=10.0.0<10.0.21
Event History
Dec 16, 2025
CVE Published
via MITRE·04:34 PM
Data Sourced
via MITRE·04:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software