Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23028 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a technician can use a malicious payload to trigger a stored XSS on the project's kanban. This is fixed in version 10.0.19. |
Mon, 04 Aug 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* |
Wed, 30 Jul 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Glpi-project
Glpi-project glpi |
|
| Vendors & Products |
Glpi-project
Glpi-project glpi |
Tue, 29 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Jul 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a technician can use a malicious payload to trigger a stored XSS on the project's kanban. This is fixed in version 10.0.19. | |
| Title | GLPI is susceptible to Stored XSS attack through project's kanban | |
| Weaknesses | CWE-79 CWE-80 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-29T18:35:50.874Z
Reserved: 2025-02-26T18:11:52.306Z
Link: CVE-2025-27514
Updated: 2025-07-29T18:35:45.942Z
Status : Analyzed
Published: 2025-07-29T18:15:25.727
Modified: 2025-08-04T18:54:02.640
Link: CVE-2025-27514
No data.
OpenCVE Enrichment
Updated: 2025-07-30T06:15:15Z
EUVD