VYPR

Vendor CVEs

Glpi Project

All CVEs

236 total · sorted by risk
  • CVE-2020-11036HigMay 5, 2020
    risk 0.49cvss 7.6epss 0.01

    In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored XSS in the comments of items in the Knowledge base. Adding a comment with content "" reproduces the attack. This can be exploited by a…

  • CVE-2020-11035HigMay 5, 2020
    risk 0.49cvss 7.5epss 0.01

    In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6.

  • CVE-2020-11032HigMay 5, 2020
    risk 0.49cvss 7.6epss 0.01

    In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician account. This is fixed in version 9.4.6.

  • CVE-2026-42321HigJun 3, 2026
    risk 0.48cvss —epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS payload in the asset locked tab. Upgrade to 10.0.25 or 11.0.7 to receive a patch.

  • CVE-2026-5385HigJun 2, 2026
    risk 0.48cvss —epss 0.00

    An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. This issue affects glpi: before 11.0.7.

  • CVE-2024-37149HigJul 10, 2024
    risk 0.48cvss 7.2epss 0.21

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated technician user can upload a malicious PHP script and hijack the plugin loader to execute this malicious script.…

  • CVE-2024-47761HigDec 11, 2024
    risk 0.47cvss 7.2epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an administrator with access to the sent notifications contents can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.

  • CVE-2026-40108HigJun 2, 2026
    risk 0.46cvss —epss 0.00

    GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. This issue has been fixed in version 11.0.7.

  • CVE-2026-26263HigApr 6, 2026
    risk 0.46cvss 8.1epss 0.08

    GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6.

  • CVE-2025-27147HigMar 25, 2025
    risk 0.46cvss 8.2epss 0.00

    The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, and data collection (files, Windows registry, WMI). Versions prior to 1.5.0 have an improper access…

  • CVE-2024-53850HigDec 26, 2024
    risk 0.46cvss 8.2epss 0.01

    The Addressing GLPI plugin enables you to create IP reports for visualize IP addresses used and free on a given network.. Starting with 3.0.0 and before 3.0.3, a poor security check allows an unauthenticated attacker to determine whether data exists (by name) in GLPI.

  • CVE-2022-34125MedApr 16, 2023
    risk 0.46cvss 6.5epss 0.05

    front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/ pathname in the file parameter.

  • CVE-2023-37278MedJul 13, 2023
    risk 0.44cvss 6.8epss 0.01

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An administrator can trigger SQL injection via dashboards administration. This vulnerability has been patched in version 10.0.9.

  • CVE-2023-22722MedJan 26, 2023
    risk 0.44cvss 6.8epss 0.01

    GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 are subject to Cross-site Scripting. An attacker can persuade a victim into opening a URL containing a payload exploiting this vulnerability. After exploited, the attacker can make…

  • CVE-2021-39213MedSep 15, 2021
    risk 0.44cvss 6.8epss 0.01

    GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in version 9.5.6. One may disable API Rest as a workaround.

  • CVE-2021-21327MedMar 8, 2021
    risk 0.44cvss 6.8epss 0.02

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 non-authenticated user can remotely instantiate object of any class existing in the GLPI environment…

  • CVE-2024-45600HigDec 26, 2024
    risk 0.43cvss 7.7epss 0.00

    Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13, an authenticated user can perform a SQL injection when the plugin is active. The vulnerability is fixed in 1.21.13.

  • CVE-2020-11033MedMay 5, 2020
    risk 0.43cvss 6.6epss 0.01

    In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User. The response contains: - All api_tokens which can be used to do privileges escalations or read/update/delete…

  • CVE-2026-26027HigApr 6, 2026
    risk 0.42cvss 7.5epss 0.00

    GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6.

  • CVE-2026-22044MedFeb 4, 2026
    risk 0.42cvss 6.5epss 0.00

    GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This issue has been patched in version 10.0.23.

  • CVE-2025-59935MedDec 16, 2025
    risk 0.42cvss 6.5epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inventory endpoint. Users should upgrade to 10.0.21 to receive a patch.

  • CVE-2025-32786HigNov 4, 2025
    risk 0.42cvss 7.5epss 0.07

    The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Versions 1.5.0 and below are vulnerable to SQL Injection. This issue is fixed in version 1.5.1.

  • CVE-2025-53105HigAug 27, 2025
    risk 0.42cvss 7.5epss 0.00

    GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 10.0.0 to before 10.0.19, a connected user without administration…

  • CVE-2025-53111MedJul 30, 2025
    risk 0.42cvss 6.5epss 0.00

    GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized access to some resources. This is fixed in version 10.0.19.

  • CVE-2025-53008MedJul 30, 2025
    risk 0.42cvss 6.5epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.3.1 through 10.0.19, a connected user can use a malicious payload to steal…

  • CVE-2025-52897MedJul 30, 2025
    risk 0.42cvss 6.5epss 0.00

    GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to attempt a phishing attack from the planning feature. This is fixed in version 10.0.19.

  • CVE-2025-21627MedFeb 25, 2025
    risk 0.42cvss 6.5epss 0.00

    GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious link can be crafted to perform a reflected XSS attack on the search page. If the anonymous ticket creation is enabled, this attack can be performed by an unauthenticated user.…

  • CVE-2024-45610MedNov 15, 2024
    risk 0.42cvss 6.5epss 0.00

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located…

  • CVE-2024-45609MedNov 15, 2024
    risk 0.42cvss 6.5epss 0.00

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the…

  • CVE-2024-45608MedNov 15, 2024
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing its preferences. Upgrade to 10.0.17.

  • CVE-2024-43418MedNov 15, 2024
    risk 0.42cvss 6.5epss 0.00

    GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.

  • CVE-2024-43417MedNov 15, 2024
    risk 0.42cvss 6.5epss 0.00

    GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the Software form. Upgrade to 10.0.17.

  • CVE-2024-41679MedNov 15, 2024
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability from the ticket form. Upgrade to 10.0.17.

  • CVE-2024-41678MedNov 15, 2024
    risk 0.42cvss 6.5epss 0.00

    GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.

  • CVE-2023-42461MedSep 27, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The ITIL actors input field from the Ticket form can be used to perform a SQL injection.…

  • CVE-2023-34244MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 9.4.0 and prior to version 10.0.8, a malicious link can be crafted by an unauthenticated user that can exploit a reflected XSS in case any authenticated user opens the crafted link. Users should upgrade…

  • CVE-2023-34107MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user, allows access to the view all KnowbaseItems. Version 10.0.8 has a patch…

  • CVE-2023-34106MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user. This allows access to the list of all users and their personal information.…

  • CVE-2023-23610MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, even those on which user is not allowed to…

  • CVE-2021-39210MedSep 15, 2021
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would be able to use it to…

  • CVE-2026-29047HigApr 6, 2026
    risk 0.40cvss 7.2epss 0.00

    GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the logs export feature. This vulnerability is fixed in 10.0.24 and 11.0.6.

  • CVE-2026-25932HigApr 6, 2026
    risk 0.40cvss 7.2epss 0.00

    GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24.

  • CVE-2023-33971MedMay 31, 2023
    risk 0.40cvss 6.1epss 0.01

    Formcreator is a GLPI plugin which allow creation of custom forms and the creation of one or more tickets when the form is filled. A probable stored cross-site scripting vulnerability is present in Formcreator 2.13.5 and prior via the use of the use of `##FULLFORM##` for…

  • CVE-2023-28639MedApr 5, 2023
    risk 0.40cvss 6.1epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 0.85 and prior to versions 9.5.13 and 10.0.7, a malicious link can be crafted by an unauthenticated user. It will be able to exploit a reflected XSS in case any authenticated user opens the crafted…

  • CVE-2023-22725MedJan 26, 2023
    risk 0.40cvss 6.2epss 0.01

    GLPI is a Free Asset and IT Management Software package. Versions 0.6.0 and above, prior to 10.0.6 are vulnerable to Cross-site Scripting. This vulnerability allow for an administrator to create a malicious external link. This issue is patched in 10.0.6.

  • CVE-2023-22724MedJan 26, 2023
    risk 0.40cvss 6.2epss 0.01

    GLPI is a Free Asset and IT Management Software package. Versions prior to 10.0.6 are subject to Cross-site Scripting via malicious RSS feeds. An Administrator can import a malicious RSS feed that contains Cross Site Scripting (XSS) payloads inside RSS links. Victims who wish to…

  • CVE-2022-41941MedJan 26, 2023
    risk 0.40cvss 6.2epss 0.01

    GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6, are subject to Cross-site Scripting. An administrator may store malicious code in help links. This issue is patched in 10.0.6.

  • CVE-2022-39181MedNov 17, 2022
    risk 0.40cvss 6.1epss 0.00

    GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS). Type 1: Reflected XSS (or Non-Persistent) - The server reads data directly from the HTTP request and reflects it back in the HTTP response. Reflected XSS exploits occur when an attacker causes a victim to…

  • CVE-2021-3486MedMay 26, 2021
    risk 0.40cvss 6.1epss 0.01

    GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.

  • CVE-2021-21325MedMar 8, 2021
    risk 0.40cvss 6.2epss 0.01

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 a new budget type can be defined by user. This input is not correctly filtered. This results in a…

Page 2 of 5