CVE Database
/

CVE-2026-40108

Back to search

CVE-2026-40108

Published: Jun 2, 2026

Modified: Jun 3, 2026

PUBLISHED

Description

GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. This issue has been fixed in version 11.0.7.

VendorProductVersions

glpi-project

glpi

affected
>= 11.0.0, < 11.0.7

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now