CVE-2025-26626

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 14, 2025
CWE ID 79

Summary

CVE-2025-26626 is a reflective cross-site scripting (XSS) vulnerability affecting the GLPI Inventory Plugin, used in versions prior to 1.5.0 for managing assets with the GLPI software. This issue allows malicious actors to inject and execute malicious JavaScript code by manipulating the plugin's input fields, potentially leading to data theft or unauthorized access. User interaction is required to exploit the vulnerability, and updating to version 1.5.0 is recommended to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share