CVE-2026-55214: GLPI: Stored XSS in suppliers
Published Sep 25, 2026
·Updated
GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the stored cross-site scripting payload. This issue is fixed in version 11.0.8.
Affected Software
1 affected component
GLPI GLPI>=11.0.6<11.0.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 11.0.8
Event History
Sep 25, 2026
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who needs to be able to exploit this issue?
An authenticated user with technician access is required to store the malicious markup in a supplier website field. The payload runs when any user opens the suppliers list for the affected item.
2
Which deployments are affected and what version fixes it?
GLPI versions from 11.0.6 through 11.0.8 are identified as affected. The issue is fixed in GLPI 11.0.8.