VYPR

Glpi

by Glpi Project

Source repositories

CVEs (203)

  • CVE-2019-14666HigSep 25, 2019
    risk 0.57cvss 8.8epss 0.02

    GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary…

  • CVE-2018-13049HigJul 2, 2018
    risk 0.57cvss 8.8epss 0.01

    The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by triggering a crafted LIMIT clause to front/computer.php.

  • CVE-2017-11475HigJul 20, 2017
    risk 0.57cvss 8.8epss 0.01

    GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.

  • CVE-2023-41326HigSep 27, 2023
    risk 0.55cvss 8.1epss 0.31

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. A logged user from any profile can hijack the Kanban feature to alter any user field,…

  • CVE-2023-41320HigSep 27, 2023
    risk 0.55cvss 8.1epss 0.32

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. UI layout preferences management can be hijacked to lead to SQL injection. This…

  • CVE-2024-37148HigJul 10, 2024
    risk 0.54cvss 8.1epss 0.20

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can exploit a SQL injection vulnerability in some AJAX scripts to alter another user account data and take…

  • CVE-2026-26026CriApr 6, 2026
    risk 0.53cvss 9.1epss 0.11

    GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.

  • CVE-2024-48912HigDec 11, 2024
    risk 0.53cvss 8.1epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated user can use an application endpoint to delete any user account. Version 10.0.17 contains a patch for this issue.

  • CVE-2023-41324HigSep 27, 2023
    risk 0.53cvss 8.1epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. An API user that have read access on users resource can steal accounts of other users.…

  • CVE-2023-35939HigJul 5, 2023
    risk 0.53cvss 8.1epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a on a file accessible by an authenticated user (or not for certain actions), allows a threat actor to interact, modify, or see Dashboard…

  • CVE-2023-28632HigApr 5, 2023
    risk 0.53cvss 8.1epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, an authenticated user can modify emails of any user, and can therefore takeover another user account through the "forgotten password" feature. By modifying…

  • CVE-2022-29250HigJun 9, 2022
    risk 0.53cvss 8.1epss 0.01

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to version 10.0.1 it is possible to add extra information by SQL injection on search pages. In order to exploit this…

  • CVE-2013-2227HigNov 1, 2019
    risk 0.53cvss 7.5epss 0.13

    GLPI 0.83.7 has Local File Inclusion in common.tabs.php.

  • CVE-2026-22248HigMar 11, 2026
    risk 0.52cvss 8.0epss 0.00

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. From 11.0.0 to before 11.0.5, an authenticated technician user can upload a malicious file and trigger its execution through an…

  • CVE-2016-7507HigJul 19, 2017
    risk 0.52cvss 8.0epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creation of an admin account in the application.

  • CVE-2016-7508HigJun 21, 2017
    risk 0.52cvss 7.5epss 0.02

    Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a certain character when the database is configured to use Big5 Asian encoding.

  • CVE-2022-39323HigNov 3, 2022
    risk 0.51cvss 7.4epss 0.34

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Time based attack using a SQL injection in api REST user_token. This issue has been…

  • CVE-2023-42462HigSep 27, 2023
    risk 0.50cvss 7.7epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The document upload process can be diverted to delete some files. Users are advised to…

  • CVE-2021-21326HigMar 8, 2021
    risk 0.50cvss 7.7epss 0.01

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 it is possible to create tickets for another user with self-service interface without delegatee systems…

  • CVE-2025-66417HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.

Page 2 of 11