CVE-2026-40108 - GLPI Vulnerable to Stored XSS in ITIL Costs
CVE ID :CVE-2026-40108
Published : June 2, 2026, 11:16 p.m. | 3 hours, 46 minutes ago
Description :GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. This issue has been fixed in version 11.0.7.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 2, 2026, 11:16 p.m. | 3 hours, 46 minutes ago
Description :GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. This issue has been fixed in version 11.0.7.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...