#glpiproject
CVE-2026-53610 - glpi
Versions of GLPI from 11.0.0 through 11.0.8 allow a specially‑made web address to display content that the attacker supplies. If a user clicks that link, the malicious content can…

Too many irrelevant or confusing CVEs? Use stackflag.com

#glpi #glpiproject #CVE #infosec
CVE-2026-53610: GLPI: Reflected XSS in dashboards
GLPI is a free asset and IT management software package.
stackflag.com
September 26, 2026 at 3:20 PM
CVE-2026-48482 - glpi
Versions 11.0.0 through 11.0.7 of the GLPI IT management tool let a user with form‑admin rights upload a specially crafted image that is saved outside the intended folder. This can…

Too many irrelevant or confusing CVEs? Use stackflag.com

#glpi #glpiproject #CVE #infosec
CVE-2026-48482: GLPI: RCE via Form import
GLPI is a free asset and IT management software package.
stackflag.com
September 26, 2026 at 3:30 PM
CVE-2026-55214 - glpi
In GLPI versions 11.0.6 through 11.0.8, a logged‑in technician can place hidden code in the supplier information fields. When any user opens the supplier list for that item, the hidden…

Too many irrelevant or confusing CVEs? Use stackflag.com

#glpi #glpiproject #CVE #infosec
CVE-2026-55214: GLPI: Stored XSS in suppliers
GLPI is a free asset and IT management software package.
stackflag.com
September 26, 2026 at 3:10 PM
CVE-2026-53625 - glpi
In GLPI versions up to 10.0.26 and 11.0.8, a technician can use the API to alter another user's login type, even a super‑admin's. This could let the technician take over that account.…

Too many irrelevant or confusing CVEs? Use stackflag.com

#glpi #glpiproject #CVE #infosec
CVE-2026-53625: GLPI: Privilege Escalation via authtype API manipulation
GLPI is a free asset and IT management software package.
stackflag.com
September 26, 2026 at 3:20 PM