Cross-site scripting in GLPI - CVE-2026-5385
Published: June 1, 2026
GLPI
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the knowledge base item content handling when processing user-supplied knowledge base content. A remote user can store a crafted xss payload in a knowledge base item to execute arbitrary script in a victim's browser.