VYPR

Glpi

by Glpi Project

Source repositories

CVEs (203)

  • CVE-2022-39277MedNov 3, 2022
    risk 0.29cvss 4.5epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. External links are not properly sanitized and can therefore be used for a…

  • CVE-2026-23624MedFeb 4, 2026
    risk 0.28cvss 4.3epss 0.00

    GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO variables, a user can steal a GLPI session previously opened by another user on the same machine. This…

  • CVE-2025-53112MedJul 30, 2025
    risk 0.28cvss 4.3epss 0.00

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.1.0 through 10.0.18, a lack of permission checks can result in unauthorized removal of some specific resources. This is fixed…

  • CVE-2025-23024MedFeb 25, 2025
    risk 0.28cvss 4.3epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 0.72 and prior to version 10.0.18, an anonymous user can disable all the active plugins. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` file.

  • CVE-2024-11955MedFeb 25, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument redirect leads to open redirect. The attack can be launched remotely. The…

  • CVE-2022-39370MedNov 3, 2022
    risk 0.28cvss 4.3epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Connected users may gain access to debug panel through the GLPI update script. This…

  • CVE-2020-27663MedNov 26, 2020
    risk 0.28cvss 4.3epss 0.01

    In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.).

  • CVE-2020-27662MedNov 26, 2020
    risk 0.28cvss 4.3epss 0.01

    In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.).

  • CVE-2026-22247MedFeb 4, 2026
    risk 0.27cvss 4.1epss 0.00

    GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issue has been patched in version 11.0.5.

  • CVE-2025-52567LowJul 30, 2025
    risk 0.23cvss 3.5epss 0.00

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 0.84 through 10.0.18, usage of RSS feeds or external calendars when planning is subject to SSRF exploit. The previous security…

  • CVE-2022-39372LowNov 3, 2022
    risk 0.23cvss 3.5epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Authenticated users may store malicious code in their account information. This…

  • CVE-2022-39276LowNov 3, 2022
    risk 0.23cvss 3.5epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Usage of RSS feeds or an external calendar in planning is subject to SSRF exploit.…

  • CVE-2026-32312MedMay 19, 2026
    risk 0.21cvss 4.3epss 0.00

    GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue has been fixed in version 11.0.7.

  • CVE-2024-37147MedJul 10, 2024
    risk 0.21cvss 4.3epss 0.01

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can attach a document to any item, even if the user has no write access on it. Upgrade to 10.0.16.

  • CVE-2025-53113LowJul 30, 2025
    risk 0.18cvss 2.7epss 0.00

    GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 0.65 through 10.0.18, a technician can use the external links…

  • CVE-2022-39376LowNov 3, 2022
    risk 0.17cvss 2.6epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Users may be able to inject custom fields values in `mailto` links. This issue has…

  • CVE-2020-15175HigOct 7, 2020
    risk 0.06cvss 7.4epss 0.71

    In GLPI before version 9.5.2, the `​pluginimage.send.php​` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete the .htaccess file for the files directory. Any user becomes able to read all the files and…

  • CVE-2024-31456HigMay 7, 2024
    risk 0.05cvss 7.7epss 0.59

    GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability from map search. This vulnerability is fixed in 10.0.15.

  • CVE-2024-29889HigMay 7, 2024
    risk 0.05cvss 7.1epss 0.63

    GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter another user account data take control of it. This vulnerability is fixed in 10.0.15.

  • CVE-2024-27096HigMar 18, 2024
    risk 0.05cvss 7.7epss 0.59

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can exploit a SQL injection vulnerability in the search engine to extract data from the database. This issue has…

Page 7 of 11