VYPR

Glpi

by Glpi Project

Source repositories

CVEs (203)

  • CVE-2026-22044MedFeb 4, 2026
    risk 0.42cvss 6.5epss 0.00

    GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This issue has been patched in version 10.0.23.

  • CVE-2025-59935MedDec 16, 2025
    risk 0.42cvss 6.5epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inventory endpoint. Users should upgrade to 10.0.21 to receive a patch.

  • CVE-2025-53105HigAug 27, 2025
    risk 0.42cvss 7.5epss 0.00

    GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 10.0.0 to before 10.0.19, a connected user without administration…

  • CVE-2025-53111MedJul 30, 2025
    risk 0.42cvss 6.5epss 0.00

    GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized access to some resources. This is fixed in version 10.0.19.

  • CVE-2025-53008MedJul 30, 2025
    risk 0.42cvss 6.5epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.3.1 through 10.0.19, a connected user can use a malicious payload to steal…

  • CVE-2025-52897MedJul 30, 2025
    risk 0.42cvss 6.5epss 0.00

    GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to attempt a phishing attack from the planning feature. This is fixed in version 10.0.19.

  • CVE-2025-21627MedFeb 25, 2025
    risk 0.42cvss 6.5epss 0.00

    GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious link can be crafted to perform a reflected XSS attack on the search page. If the anonymous ticket creation is enabled, this attack can be performed by an unauthenticated user.…

  • CVE-2024-45610MedNov 15, 2024
    risk 0.42cvss 6.5epss 0.00

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located…

  • CVE-2024-45609MedNov 15, 2024
    risk 0.42cvss 6.5epss 0.00

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the…

  • CVE-2024-45608MedNov 15, 2024
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing its preferences. Upgrade to 10.0.17.

  • CVE-2024-43418MedNov 15, 2024
    risk 0.42cvss 6.5epss 0.00

    GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.

  • CVE-2024-43417MedNov 15, 2024
    risk 0.42cvss 6.5epss 0.00

    GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the Software form. Upgrade to 10.0.17.

  • CVE-2024-41679MedNov 15, 2024
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability from the ticket form. Upgrade to 10.0.17.

  • CVE-2024-41678MedNov 15, 2024
    risk 0.42cvss 6.5epss 0.00

    GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.

  • CVE-2023-42461MedSep 27, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The ITIL actors input field from the Ticket form can be used to perform a SQL injection.…

  • CVE-2023-34244MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 9.4.0 and prior to version 10.0.8, a malicious link can be crafted by an unauthenticated user that can exploit a reflected XSS in case any authenticated user opens the crafted link. Users should upgrade…

  • CVE-2023-34107MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user, allows access to the view all KnowbaseItems. Version 10.0.8 has a patch…

  • CVE-2023-34106MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user. This allows access to the list of all users and their personal information.…

  • CVE-2023-23610MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, even those on which user is not allowed to…

  • CVE-2021-39210MedSep 15, 2021
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would be able to use it to…

Page 4 of 11