CVE Watchtower β Back to CVE ListCVE-2026-5385NVDDescriptionAn unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. This issue affects glpi: before 11.0.7.Severity LevelUNKNOWNPublished Date02/06/2026Last Modified02/06/2026Exploitation Status????Referenceshttps://fluidattacks.com/es/advisories/bizkithttps://github.com/glpi-project/glpihttps://github.com/glpi-project/glpi/security/advisories/GHSA-2fg5-jg72-h338https://github.com/glpi-project/glpi/releases/tag/11.0.7