VYPR

Tag Plugin

by Glpi Project

CVEs (1)

  • CVE-2026-53987Jul 9, 2026
    risk 0.00cvss epss 0.00

    The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban badge markup via PluginTagTag::preKanbanContent() without output escaping, resulting in stored cross-site scripting. An authenticated user with TAG MANAGEMENT…