CVE-2025-27514mediumCWE-79CWE-80

CVE-2025-27514: medium-severity vulnerability in glpi-project glpi

GLPI is susceptible to Stored XSS attack through project's kanban

Published

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.5epss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a technician can use a malicious payload to trigger a stored XSS on the project's kanban. This is fixed in version 10.0.19.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Affected products
glpi-project · glpi