Review reviewHigh
CVE-2026-5385
glpi-project glpi
An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. This issue affects glpi: before 11.0.7.
- CVSS
- 8.4
- EPSS
- 0.42% 34.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.03