CVE-2026-25932: GLPI has Stored XSS in Supplier 'Website' field
Published Apr 6, 2026
·Updated
GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=0.60<10.0.24
Event History
Apr 6, 2026
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-25932?
CVE-2026-25932 is categorized as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2026-25932?
To remediate CVE-2026-25932, upgrade GLPI to version 10.0.24 or later.
3
Who is affected by CVE-2026-25932?
Authenticated technician users of GLPI versions between 0.60 and 10.0.24 are affected by CVE-2026-25932.
4
What type of vulnerability is CVE-2026-25932?
CVE-2026-25932 is a stored cross-site scripting (XSS) vulnerability found in the Supplier 'Website' field.
5
When was CVE-2026-25932 disclosed?
CVE-2026-25932 was disclosed alongside its fix in version 10.0.24 of GLPI.