CVE-2026-25590: GLPI-Project GLPI Inventory

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, there is a reflected XSS vulnerability in task jobs. This vulnerability is fixed in 1.6.6.

Affected products

Published 2026-03-03. Last modified 2026-06-17.