VYPR
Vendor

Glpi Project

Products
35
CVEs
249
Across products
263
Status
Private

Products

35
View all 35 products →

Recent CVEs

249
View all 249 CVEs →
  • CVE-2022-35914CriKEVSep 19, 2022
    risk 0.87cvss 9.8epss 1.00

    /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

  • CVE-2022-34128CriApr 16, 2023
    risk 0.67cvss 9.8epss 0.08

    The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.

  • CVE-2022-31056CriJun 28, 2022
    risk 0.67cvss 9.8epss 0.09

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved…

  • CVE-2023-42802CriNov 2, 2023
    risk 0.65cvss 10.0epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation allows one to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system…

  • CVE-2023-28849CriApr 5, 2023
    risk 0.65cvss 10.0epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.7, GLPI inventory endpoint can be used to drive a SQL injection attack. It can also be used to store malicious code that could be used to perform XSS attack. By default,…

  • CVE-2021-43779CriJan 5, 2022
    risk 0.65cvss 9.9epss 0.09

    GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to the server's underlying operating system using command…

  • CVE-2019-10232CriMar 27, 2019
    risk 0.65cvss 9.8epss 0.22

    Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.

  • CVE-2025-21619CriMar 18, 2025
    risk 0.64cvss 9.8epss 0.00

    GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This vulnerability is fixed in 10.0.18.

  • CVE-2024-31705CriApr 29, 2024
    risk 0.64cvss 9.8epss 0.02

    An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of user-supplied input.

  • CVE-2021-44617CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.

  • CVE-2019-12530CriJun 2, 2019
    risk 0.64cvss 9.8epss 0.02

    Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf.php, and uptime.php in front/sh.

  • CVE-2019-10231CriMar 27, 2019
    risk 0.64cvss 9.8epss 0.03

    Teclib GLPI before 9.4.1.1 is affected by a PHP type juggling vulnerability allowing bypass of authentication. This occurs in Auth::checkPassword() (inc/auth.class.php).

  • CVE-2017-11184CriJul 28, 2017
    risk 0.64cvss 9.8epss 0.02

    SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.

  • CVE-2017-11474CriJul 20, 2017
    risk 0.64cvss 9.8epss 0.01

    GLPI before 9.1.5.1 has SQL Injection in the $crit variable in inc/computer_softwareversion.class.php, exploitable via ajax/common.tabs.php.

  • CVE-2017-11329CriJul 17, 2017
    risk 0.64cvss 9.8epss 0.01

    GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers.

  • CVE-2021-43778CriNov 24, 2021
    risk 0.63cvss 9.1epss 0.53

    Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal vulnerability. This issue was patched in version 2.6.1. As a workaround, delete the…

  • CVE-2023-28838CriApr 5, 2023
    risk 0.62cvss 9.6epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 9.5.13 and 10.0.7, a SQL Injection vulnerability allow users with access rights to statistics or reports to extract all data from database and, in some cases, write a webshell…

  • CVE-2023-35924HigJul 5, 2023
    risk 0.60cvss 8.6epss 0.51

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory endpoint can be used to drive a SQL injection attack. By default, GLPI inventory endpoint requires no authentication. Version 10.0.8 has a patch for…

  • CVE-2025-24799HigMar 18, 2025
    risk 0.59cvss 7.5epss 0.87

    GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.

  • CVE-2023-36808HigJul 5, 2023
    risk 0.59cvss 8.6epss 0.48

    GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack. Version 10.0.8 has a patch for this issue. As a workaround, one…