VYPR

Vendor CVEs

Glpi Project

All CVEs

236 total · sorted by risk
  • CVE-2020-11034MedMay 5, 2020
    risk 0.40cvss 6.1epss 0.08

    In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6.

  • CVE-2026-44281HigJun 3, 2026
    risk 0.39cvss —epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user with config READ permission can read a specific asset object. Upgrade to 11.0.7 or 10.0.25 to receive a patch.

  • CVE-2026-42318HigJun 3, 2026
    risk 0.39cvss —epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI. Upgrade to 11.0.7 or 10.0.25 to receive a patch. As a workaround, disable…

  • CVE-2026-42317HigJun 3, 2026
    risk 0.39cvss —epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, a technician can delete arbitrary files from the filesystem as long as the webserver has write rights on them. Upgrade to 10.0.25 or 11.0.7 to receive a…

  • CVE-2026-26001HigMar 18, 2026
    risk 0.39cvss 7.1epss 0.00

    The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, non sanitized user input can lend to an SQL injection from reports, with adequate rights. This vulnerability is fixed in 1.6.6.

  • CVE-2025-21626MedFeb 25, 2025
    risk 0.38cvss 5.8epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive information from the `status.php` endpoint. Version 10.0.18 contains a fix for the issue. Some workarounds are available. One may…

  • CVE-2022-31062MedJun 20, 2022
    risk 0.38cvss 5.3epss 0.06

    ### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used.

  • CVE-2024-45611MedNov 15, 2024
    risk 0.37cvss 5.7epss 0.00

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can bypass the access control policy to create a private RSS feed attached to another user account and use a…

  • CVE-2023-41323MedSep 27, 2023
    risk 0.37cvss 5.3epss 0.34

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. An unauthenticated user can enumerate users logins. Users are advised to upgrade to…

  • CVE-2024-50339MedDec 12, 2024
    risk 0.36cvss 5.3epss 0.19

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version 10.0.17 contains a patch for this issue.

  • CVE-2026-11321MedJul 10, 2026
    risk 0.35cvss 6.4epss 0.00

    The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL queries during CSV import, without parameterization or escaping, resulting in authenticated SQL injection. An authenticated user with access to the Data…

  • CVE-2026-25937MedMar 18, 2026
    risk 0.35cvss 6.5epss 0.00

    GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor with knowledge of a user's credentials can bypass MFA and steal their account. Version 11.0.6 fixes the issue.

  • CVE-2026-25936MedMar 17, 2026
    risk 0.35cvss 6.5epss 0.00

    GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injection. Version 11.0.6 fixes the issue.

  • CVE-2025-53357MedJul 30, 2025
    risk 0.35cvss 5.4epss 0.00

    GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 0.78 through 10.0.18, a connected user can alter the reservations of…

  • CVE-2025-27153MedJul 1, 2025
    risk 0.35cvss 6.5epss 0.00

    Escalade GLPI plugin is a ticket escalation process helper for GLPI. Prior to version 2.9.11, there is an improper access control vulnerability. This can lead to data exposure and workflow disruptions. This issue has been patched in version 2.9.11.

  • CVE-2025-26626MedMar 14, 2025
    risk 0.35cvss 6.5epss 0.00

    The GLPI Inventory Plugin handles various types of tasks for GLPI agents for the GLPI asset and IT management software package. Versions prior to 1.5.0 are vulnerable to reflective cross-site scripting, which may lead to executing javascript code. Version 1.5.0 fixes the issue.

  • CVE-2025-25192MedFeb 25, 2025
    risk 0.35cvss 6.5epss 0.01

    GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive information. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` file.

  • CVE-2021-39211MedSep 15, 2021
    risk 0.35cvss 5.3epss 0.05

    GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI and server information. This issue is fixed in version 9.5.6. As a workaround, remove the file `ajax/telemetry.php`, which is not…

  • CVE-2021-21314MedMar 3, 2021
    risk 0.35cvss 5.4epss 0.01

    GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is an XSS vulnerability involving a logged in user while updating a ticket.

  • CVE-2021-21312MedMar 3, 2021
    risk 0.35cvss 5.4epss 0.01

    GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is a vulnerability within the document upload function (Home > Management > Documents > Add, or…

  • CVE-2019-1010307MedJul 15, 2019
    risk 0.35cvss 5.4epss 0.01

    GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege escalation and executing js on admin. The component is: /glpi/ajax/getDropDownValue.php. The attack vector is: 1- User Create a…

  • CVE-2016-7509MedJul 19, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to inject arbitrary web script or HTML by attaching a crafted HTML file to a ticket.

  • CVE-2023-53943MedDec 18, 2025
    risk 0.34cvss 5.3epss 0.00

    GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email addresses by submitting requests to the password reset endpoint and analyzing response…

  • CVE-2024-38370MedNov 15, 2024
    risk 0.34cvss 5.3epss 0.00

    GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API without appropriate rights. Upgrade to 10.0.16.

  • CVE-2023-41888MedSep 27, 2023
    risk 0.34cvss 5.3epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The lack of path filtering on the GLPI URL may allow an attacker to transmit a malicious…

  • CVE-2022-39262MedNov 3, 2022
    risk 0.34cvss 5.2epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package, GLPI administrator can define rich-text content to be displayed on login page. The displayed content is can contains malicious code that can be used to steal…

  • CVE-2023-41322MedSep 27, 2023
    risk 0.32cvss 4.9epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. A user with write access to another user can make requests to change the latter's…

  • CVE-2023-41321MedSep 27, 2023
    risk 0.32cvss 4.9epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. An API user can enumerate sensitive fields values on resources on which he has read…

  • CVE-2022-39373MedNov 3, 2022
    risk 0.32cvss 4.9epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Administrator may store malicious code in entity name. This issue has been patched,…

  • CVE-2021-21313MedMar 3, 2021
    risk 0.32cvss 4.9epss 0.01

    GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is a vulnerability in the /ajax/common.tabs.php endpoint, indeed, at least two parameters _target…

  • CVE-2017-11183MedJul 28, 2017
    risk 0.32cvss 4.9epss 0.02

    front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.

  • CVE-2026-42320MedJun 3, 2026
    risk 0.31cvss —epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arbitrary files inside the GLPI_DOC_DIR. Upgrade to 10.0.25 or 11.0.7 to receive a patch.

  • CVE-2024-47759MedNov 15, 2024
    risk 0.31cvss 4.8epss 0.00

    GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. The script will then be executed when any user will try to see the document contents. Upgrade to 10.0.17.

  • CVE-2023-28852MedApr 5, 2023
    risk 0.31cvss 4.8epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 9.5.13 and 10.0.7, a user with dashboard administration rights may hack the dashboard form to store malicious code that will be executed when other users will use the related…

  • CVE-2022-39234MedNov 3, 2022
    risk 0.31cvss 4.7epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Deleted/deactivated user could continue to use their account as long as its cookie…

  • CVE-2026-25590MedMar 3, 2026
    risk 0.29cvss 4.5epss 0.00

    The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, there is a reflected XSS vulnerability in task jobs. This vulnerability is fixed in 1.6.6.

  • CVE-2023-28636MedApr 5, 2023
    risk 0.29cvss 4.5epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 0.60 and prior to versions 9.5.13 and 10.0.7, a vulnerability allows an administrator to create a malicious external link. This issue is fixed in versions 9.5.13 and 10.0.7.

  • CVE-2022-39375MedNov 3, 2022
    risk 0.29cvss 4.5epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Users may be able to create a public RSS feed to inject malicious code in…

  • CVE-2022-39277MedNov 3, 2022
    risk 0.29cvss 4.5epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. External links are not properly sanitized and can therefore be used for a…

  • CVE-2026-23624MedFeb 4, 2026
    risk 0.28cvss 4.3epss 0.00

    GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO variables, a user can steal a GLPI session previously opened by another user on the same machine. This…

  • CVE-2025-53112MedJul 30, 2025
    risk 0.28cvss 4.3epss 0.00

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.1.0 through 10.0.18, a lack of permission checks can result in unauthorized removal of some specific resources. This is fixed…

  • CVE-2025-23024MedFeb 25, 2025
    risk 0.28cvss 4.3epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 0.72 and prior to version 10.0.18, an anonymous user can disable all the active plugins. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` file.

  • CVE-2024-11955MedFeb 25, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument redirect leads to open redirect. The attack can be launched remotely. The…

  • CVE-2022-39370MedNov 3, 2022
    risk 0.28cvss 4.3epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Connected users may gain access to debug panel through the GLPI update script. This…

  • CVE-2021-30144MedApr 6, 2021
    risk 0.28cvss 4.3epss 0.01

    The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category. For example, plugins/dashboard/front/main2.php can be used.

  • CVE-2020-27663MedNov 26, 2020
    risk 0.28cvss 4.3epss 0.01

    In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.).

  • CVE-2020-27662MedNov 26, 2020
    risk 0.28cvss 4.3epss 0.01

    In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.).

  • CVE-2026-22247MedFeb 4, 2026
    risk 0.27cvss 4.1epss 0.00

    GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issue has been patched in version 11.0.5.

  • CVE-2025-52567LowJul 30, 2025
    risk 0.23cvss 3.5epss 0.00

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 0.84 through 10.0.18, usage of RSS feeds or external calendars when planning is subject to SSRF exploit. The previous security…

  • CVE-2022-39372LowNov 3, 2022
    risk 0.23cvss 3.5epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Authenticated users may store malicious code in their account information. This…