CVE-2026-55214

high

Description

GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the stored cross-site scripting payload. This issue is fixed in version 11.0.8.

References

https://github.com/glpi-project/glpi/security/advisories/GHSA-8v8p-w8mq-wqcg

https://github.com/glpi-project/glpi/releases/tag/11.0.8

https://github.com/glpi-project/glpi/commit/970786ed3b817c4c2bf90b8457b024ec566b1bfc

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87283

Details

Source: Mitre, NVD

Published: 2026-09-25

Updated: 2026-09-29

Risk Information

CVSS v2

Base Score: 3.5

Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 5.4

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

CVSS v4

Base Score: 8.5

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00278