Skip to main content

Vendor/product archive

glpi-project / glpi CVEs

Beta · best-effort

189 CVEs tagged to glpi-project / glpi14 Critical, 63 High, 104 Medium, 8 Low, 0 Unrated.

CVE-2026-32312

Published May 19, 2026

GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthoriz…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-29047

Published Apr 6, 2026

GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the logs export feature. T…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-26263

Published Apr 6, 2026

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulne…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-26027

Published Apr 6, 2026

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulner…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-26026

Published Apr 6, 2026

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25932

Published Apr 6, 2026

GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerab…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-23624

Published Feb 4, 2026

GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO varia…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-22247

Published Feb 4, 2026

GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issu…

CVSS 4.1 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-22044

Published Feb 4, 2026

GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This issue has been patched in ver…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-66417

Published Jan 15, 2026

GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerabil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64516

Published Jan 15, 2026

GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-53943

Published Dec 18, 2025

GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically te…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64520

Published Dec 16, 2025

GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge bas…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59935

Published Dec 16, 2025

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inve…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53357

Published Jul 30, 2025

GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53113

Published Jul 30, 2025

GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-53112

Published Jul 30, 2025

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.1.0 through 10.0.18, a la…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53111

Published Jul 30, 2025

GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized access to some resources. This is…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53008

Published Jul 30, 2025

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and softwar…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52897

Published Jul 30, 2025

GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to attempt a phishing attack from the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52567

Published Jul 30, 2025

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 0.84 through 10.0.18, usag…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-27514

Published Jul 29, 2025

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a t…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24801

Published Mar 18, 2025

GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-24799

Published Mar 18, 2025

GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-21619

Published Mar 18, 2025

GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This vulnerability is fixed in 10.…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 189 CVEsPage 1 of 8