VYPR

Vendor CVEs

Glpi Project

All CVEs

236 total · sorted by risk
  • CVE-2022-35914CriKEVSep 19, 2022
    risk 0.87cvss 9.8epss 1.00

    /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

  • CVE-2022-34128CriApr 16, 2023
    risk 0.67cvss 9.8epss 0.08

    The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.

  • CVE-2022-31056CriJun 28, 2022
    risk 0.67cvss 9.8epss 0.09

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved…

  • CVE-2023-42802CriNov 2, 2023
    risk 0.65cvss 10.0epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation allows one to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system…

  • CVE-2023-28849CriApr 5, 2023
    risk 0.65cvss 10.0epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.7, GLPI inventory endpoint can be used to drive a SQL injection attack. It can also be used to store malicious code that could be used to perform XSS attack. By default,…

  • CVE-2025-21619CriMar 18, 2025
    risk 0.64cvss 9.8epss 0.00

    GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This vulnerability is fixed in 10.0.18.

  • CVE-2024-31705CriApr 29, 2024
    risk 0.64cvss 9.8epss 0.02

    An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of user-supplied input.

  • CVE-2021-44617CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.

  • CVE-2017-11184CriJul 28, 2017
    risk 0.64cvss 9.8epss 0.02

    SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.

  • CVE-2017-11474CriJul 20, 2017
    risk 0.64cvss 9.8epss 0.01

    GLPI before 9.1.5.1 has SQL Injection in the $crit variable in inc/computer_softwareversion.class.php, exploitable via ajax/common.tabs.php.

  • CVE-2017-11329CriJul 17, 2017
    risk 0.64cvss 9.8epss 0.01

    GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers.

  • CVE-2023-28838CriApr 5, 2023
    risk 0.62cvss 9.6epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 9.5.13 and 10.0.7, a SQL Injection vulnerability allow users with access rights to statistics or reports to extract all data from database and, in some cases, write a webshell…

  • CVE-2023-35924HigJul 5, 2023
    risk 0.60cvss 8.6epss 0.51

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory endpoint can be used to drive a SQL injection attack. By default, GLPI inventory endpoint requires no authentication. Version 10.0.8 has a patch for…

  • CVE-2025-24799HigMar 18, 2025
    risk 0.59cvss 7.5epss 0.86

    GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.

  • CVE-2023-36808HigJul 5, 2023
    risk 0.59cvss 8.6epss 0.48

    GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack. Version 10.0.8 has a patch for this issue. As a workaround, one…

  • CVE-2025-24801HigMar 18, 2025
    risk 0.57cvss 8.5epss 0.18

    GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18.

  • CVE-2024-47760HigDec 11, 2024
    risk 0.57cvss 8.8epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with an access to the API can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.

  • CVE-2024-47758HigDec 11, 2024
    risk 0.57cvss 8.8epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the API to take control of any user that have the same or a lower level of privileges. Version 10.0.17 contains a patch for this issue.

  • CVE-2024-27756HigMar 15, 2024
    risk 0.57cvss 8.8epss 0.01

    GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.

  • CVE-2023-28634HigApr 5, 2023
    risk 0.57cvss 8.8epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, a user who has the Technician profile could see and generate a Personal token for a Super-Admin. Using such token it is possible to negotiate a GLPI session…

  • CVE-2021-39209HigSep 15, 2021
    risk 0.57cvss 8.8epss 0.01

    GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cross-Site Request Forgery (CSRF) protection in many places. This could allow a malicious actor to perform many actions on GLPI. This issue is fixed in…

  • CVE-2019-14666HigSep 25, 2019
    risk 0.57cvss 8.8epss 0.02

    GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary…

  • CVE-2018-13049HigJul 2, 2018
    risk 0.57cvss 8.8epss 0.01

    The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by triggering a crafted LIMIT clause to front/computer.php.

  • CVE-2017-11475HigJul 20, 2017
    risk 0.57cvss 8.8epss 0.01

    GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.

  • CVE-2023-41326HigSep 27, 2023
    risk 0.55cvss 8.1epss 0.31

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. A logged user from any profile can hijack the Kanban feature to alter any user field,…

  • CVE-2023-41320HigSep 27, 2023
    risk 0.55cvss 8.1epss 0.32

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. UI layout preferences management can be hijacked to lead to SQL injection. This…

  • CVE-2024-37148HigJul 10, 2024
    risk 0.54cvss 8.1epss 0.20

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can exploit a SQL injection vulnerability in some AJAX scripts to alter another user account data and take…

  • CVE-2026-26026CriApr 6, 2026
    risk 0.53cvss 9.1epss 0.11

    GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.

  • CVE-2024-48912HigDec 11, 2024
    risk 0.53cvss 8.1epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated user can use an application endpoint to delete any user account. Version 10.0.17 contains a patch for this issue.

  • CVE-2023-41324HigSep 27, 2023
    risk 0.53cvss 8.1epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. An API user that have read access on users resource can steal accounts of other users.…

  • CVE-2023-35939HigJul 5, 2023
    risk 0.53cvss 8.1epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a on a file accessible by an authenticated user (or not for certain actions), allows a threat actor to interact, modify, or see Dashboard…

  • CVE-2023-28632HigApr 5, 2023
    risk 0.53cvss 8.1epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, an authenticated user can modify emails of any user, and can therefore takeover another user account through the "forgotten password" feature. By modifying…

  • CVE-2022-29250HigJun 9, 2022
    risk 0.53cvss 8.1epss 0.01

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to version 10.0.1 it is possible to add extra information by SQL injection on search pages. In order to exploit this…

  • CVE-2013-2227HigNov 1, 2019
    risk 0.53cvss 7.5epss 0.13

    GLPI 0.83.7 has Local File Inclusion in common.tabs.php.

  • CVE-2026-23489CriMar 16, 2026
    risk 0.52cvss 9.1epss 0.00

    Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3.

  • CVE-2026-22248HigMar 11, 2026
    risk 0.52cvss 8.0epss 0.00

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. From 11.0.0 to before 11.0.5, an authenticated technician user can upload a malicious file and trigger its execution through an…

  • CVE-2022-34127HigApr 16, 2023
    risk 0.52cvss 7.5epss 0.07

    The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter.

  • CVE-2016-7507HigJul 19, 2017
    risk 0.52cvss 8.0epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creation of an admin account in the application.

  • CVE-2016-7508HigJun 21, 2017
    risk 0.52cvss 7.5epss 0.02

    Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a certain character when the database is configured to use Big5 Asian encoding.

  • CVE-2022-39323HigNov 3, 2022
    risk 0.51cvss 7.4epss 0.34

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Time based attack using a SQL injection in api REST user_token. This issue has been…

  • CVE-2023-42462HigSep 27, 2023
    risk 0.50cvss 7.7epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The document upload process can be diverted to delete some files. Users are advised to…

  • CVE-2021-21326HigMar 8, 2021
    risk 0.50cvss 7.7epss 0.01

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 it is possible to create tickets for another user with self-service interface without delegatee systems…

  • CVE-2025-66417HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.

  • CVE-2025-23046HigFeb 25, 2025
    risk 0.49cvss 7.5epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.18, if a "Mail servers" authentication provider is configured to use an Oauth connection provided by the OauthIMAP plugin, anyone can connect to GLPI using a user name on…

  • CVE-2024-40638HigNov 15, 2024
    risk 0.49cvss 8.1epss 0.37

    GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17.

  • CVE-2023-35940HigJul 5, 2023
    risk 0.49cvss 7.5epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue.

  • CVE-2023-34254HigJun 23, 2023
    risk 0.49cvss 7.6epss 0.01

    The GLPI Agent is a generic management agent. Prior to version 1.5, if glpi-agent is running remoteinventory task against an Unix platform with ssh command, an administrator user on the remote can manage to inject a command in a specific workflow the agent would run with the…

  • CVE-2022-34126HigApr 16, 2023
    risk 0.49cvss 7.5epss 0.01

    The Activity plugin before 3.1.1 for GLPI allows reading local files via directory traversal in the front/cra.send.php file parameter.

  • CVE-2023-22500HigJan 26, 2023
    risk 0.49cvss 7.5epss 0.01

    GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6 are vulnerable to Incorrect Authorization. This vulnerability allow unauthorized access to inventory files. Thus, if anonymous access to FAQ is allowed, inventory files are…

  • CVE-2022-39371HigNov 3, 2022
    risk 0.49cvss 7.5epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Script related HTML tags in assets inventory information are not properly…

Page 1 of 5