Cross-site scripting in GLPI Inventory plugin - CVE-2025-26626
Published: March 14, 2025 / Updated: April 27, 2026
GLPI Inventory plugin
Detailed vulnerability description
The vulnerability allows a remote attacker to execute javascript code.
The vulnerability exists due to cross-site scripting in the GLPI Inventory plugin when handling crafted web input. A remote attacker can send a specially crafted request to execute javascript code.
User interaction is required for exploitation.