CVE-2025-21627: GLPI-Project GLPI
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious link can be crafted to perform a reflected XSS attack on the search page. If the anonymous ticket creation is enabled, this attack can be performed by an unauthenticated user. Version 10.0.18 contains a fix for the issue.
Affected products
- GLPI-Project GLPI: before 10.0.18 (fixed in 10.0.18)
Published 2025-02-25. Last modified 2026-06-17.