VYPR

Glpi

by Glpi Project

Source repositories

CVEs (203)

  • CVE-2025-23046HigFeb 25, 2025
    risk 0.49cvss 7.5epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.18, if a "Mail servers" authentication provider is configured to use an Oauth connection provided by the OauthIMAP plugin, anyone can connect to GLPI using a user name on…

  • CVE-2024-40638HigNov 15, 2024
    risk 0.49cvss 8.1epss 0.37

    GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17.

  • CVE-2023-35940HigJul 5, 2023
    risk 0.49cvss 7.5epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue.

  • CVE-2023-22500HigJan 26, 2023
    risk 0.49cvss 7.5epss 0.01

    GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6 are vulnerable to Incorrect Authorization. This vulnerability allow unauthorized access to inventory files. Thus, if anonymous access to FAQ is allowed, inventory files are…

  • CVE-2022-39371HigNov 3, 2022
    risk 0.49cvss 7.5epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Script related HTML tags in assets inventory information are not properly…

  • CVE-2020-11036HigMay 5, 2020
    risk 0.49cvss 7.6epss 0.01

    In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored XSS in the comments of items in the Knowledge base. Adding a comment with content "" reproduces the attack. This can be exploited by a…

  • CVE-2020-11035HigMay 5, 2020
    risk 0.49cvss 7.5epss 0.01

    In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6.

  • CVE-2020-11032HigMay 5, 2020
    risk 0.49cvss 7.6epss 0.01

    In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician account. This is fixed in version 9.4.6.

  • CVE-2026-42321HigJun 3, 2026
    risk 0.48cvss epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS payload in the asset locked tab. Upgrade to 10.0.25 or 11.0.7 to receive a patch.

  • CVE-2026-5385HigJun 2, 2026
    risk 0.48cvss epss 0.00

    An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. This issue affects glpi: before 11.0.7.

  • CVE-2024-37149HigJul 10, 2024
    risk 0.48cvss 7.2epss 0.21

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated technician user can upload a malicious PHP script and hijack the plugin loader to execute this malicious script.…

  • CVE-2024-47761HigDec 11, 2024
    risk 0.47cvss 7.2epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an administrator with access to the sent notifications contents can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.

  • CVE-2026-40108HigJun 2, 2026
    risk 0.46cvss epss 0.00

    GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. This issue has been fixed in version 11.0.7.

  • CVE-2026-26263HigApr 6, 2026
    risk 0.46cvss 8.1epss 0.09

    GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6.

  • CVE-2023-37278MedJul 13, 2023
    risk 0.44cvss 6.8epss 0.01

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An administrator can trigger SQL injection via dashboards administration. This vulnerability has been patched in version 10.0.9.

  • CVE-2023-22722MedJan 26, 2023
    risk 0.44cvss 6.8epss 0.01

    GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 are subject to Cross-site Scripting. An attacker can persuade a victim into opening a URL containing a payload exploiting this vulnerability. After exploited, the attacker can make…

  • CVE-2021-39213MedSep 15, 2021
    risk 0.44cvss 6.8epss 0.01

    GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in version 9.5.6. One may disable API Rest as a workaround.

  • CVE-2021-21327MedMar 8, 2021
    risk 0.44cvss 6.8epss 0.02

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 non-authenticated user can remotely instantiate object of any class existing in the GLPI environment…

  • CVE-2020-11033MedMay 5, 2020
    risk 0.43cvss 6.6epss 0.01

    In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User. The response contains: - All api_tokens which can be used to do privileges escalations or read/update/delete…

  • CVE-2026-26027HigApr 6, 2026
    risk 0.42cvss 7.5epss 0.00

    GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6.

Page 3 of 11