
CVE-2026-25932 · NIST 7.2/10 https://nvd.nist.gov/vuln/detail/CVE-2026-25932
Post summary
The content references CVE-2026-25932 and its NIST score but offers no further detail or actionable information.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-03-03 | 1 | Patch1 |
| 2026-04-06 | 2 | Disclosure2 |
| 2026-04-07 | 1 | General1 |

CVE-2026-25932 · NIST 7.2/10 https://nvd.nist.gov/vuln/detail/CVE-2026-25932
Post summary
The content references CVE-2026-25932 and its NIST score but offers no further detail or actionable information.

2️⃣ GLPI 10.0.24 : Also, an XSS ([SECURITY - High] Stored XSS in Supplier CVE-2026-25932) and [SECURITY - High] Authenticated SQL Injection (CVE requested) have been detected on 10.0 branch, so a new version is also available today.
Post summary
GLPI 10.0.24 release includes patches for a stored XSS (CVE-2026-25932) and an authenticated SQL injection, addressing high severity vulnerabilities.

🚨*CVE* CVE-2026-25932 GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. … https://www.cve.org/CVERecord?id=CVE-2026-25932 ----- Traducción: CVE-2026-25932 GLP… http://infoflow.cloud`
Post summary
The post announces CVE‑2026‑25932, describing it as an XSS flaw in GLPI that allows authenticated technician users to inject payloads into supplier fields.

CVE-2026-25932 GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. … https://www.cve.org/CVERecord?id=CVE-2026-25932
Post summary
The message details an XSS flaw in GLPI versions prior to 10.0.24 that allows authenticated technicians to store malicious payloads, but no PoC, patch, or exploitation evidence is provided.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | glpi-project | glpi | - | - | - |