CVE-2025-59935

MEDIUM

GLPI 10.0.0-10.0.20 - Unauthenticated Stored Cross-Site Scripting via Inventory Endpoint

Title source: llm
STIX 2.1

Description

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inventory endpoint. Users should upgrade to 10.0.21 to receive a patch.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0006
EPSS Percentile 18.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
glpi-project/glpi 10.0.0 - 10.0.21
Published Dec 16, 2025
Tracked Since Feb 18, 2026