Vulnerability Description
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a technician can use a malicious payload to trigger a stored XSS on the project's kanban. This is fixed in version 10.0.19.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Glpi-Project | Glpi | >= 9.5.0, < 10.0.19 |
Related Weaknesses (CWE)
References
- https://github.com/glpi-project/glpi/commit/c340a64a11343bde706d1cd41e4be798dd92Patch
- https://github.com/glpi-project/glpi/security/advisories/GHSA-jh8j-gqxc-6gqjVendor Advisory
FAQ
What is CVE-2025-27514?
CVE-2025-27514 is a vulnerability with a CVSS score of 4.5 (MEDIUM). GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a technician can use a m...
How severe is CVE-2025-27514?
CVE-2025-27514 has been rated MEDIUM with a CVSS base score of 4.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-27514?
Check the references section above for vendor advisories and patch information. Affected products include: Glpi-Project Glpi.