Glpi-Project Glpi vulnerabilities
193 known vulnerabilities affecting glpi-project/glpi.
Total CVEs
193
CISA KEV
1
actively exploited
Public exploits
15
Exploited in wild
1
Severity breakdown
CRITICAL27HIGH53MEDIUM111LOW2
Vulnerabilities
Page 1 of 10
CVE-2026-26263CRITICALCVSS 9.8≥ 11.0.0, < 11.0.6v>= 11.0.0, < 11.0.62026-04-06
CVE-2026-26263 [CRITICAL] CWE-89 CVE-2026-26263: GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenti
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6.
nvd
CVE-2026-29047HIGHCVSS 8.8≥ 10.0.0, < 10.0.24≥ 11.0.0, < 11.0.6+2 more2026-04-06
CVE-2026-29047 [HIGH] CWE-89 CVE-2026-29047: GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, a
GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the logs export feature. This vulnerability is fixed in 10.0.24 and 11.0.6.
nvd
CVE-2026-26026HIGHCVSS 7.2≥ 11.0.0, < 11.0.6v>= 11.0.0, < 11.0.62026-04-06
CVE-2026-26026 [HIGH] CWE-94 CVE-2026-26026: GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template inje
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.
nvd
CVE-2026-25932MEDIUMCVSS 4.8≥ 0.60, < 10.0.24v>= 0.60, < 10.0.242026-04-06
CVE-2026-25932 [MEDIUM] CWE-79 CVE-2026-25932: GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticat
GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24.
nvd
CVE-2026-26027MEDIUMCVSS 6.1≥ 11.0.0, < 11.0.6v>= 11.0.0, < 11.0.62026-04-06
CVE-2026-26027 [MEDIUM] CWE-79 CVE-2026-26027: GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenti
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6.
nvd
CVE-2026-25937MEDIUMCVSS 6.5v>= 11.0.0, < 11.0.62026-03-18
CVE-2026-25937 [MEDIUM] CWE-287 CVE-2026-25937: GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to ver
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor with knowledge of a user's credentials can bypass MFA and steal their account. Version 11.0.6 fixes the issue.
nvd
CVE-2026-25936HIGHCVSS 8.8v>= 11.0.0, < 11.0.62026-03-17
CVE-2026-25936 [HIGH] CWE-89 CVE-2026-25936: GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to ver
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injection. Version 11.0.6 fixes the issue.
nvd
CVE-2026-22248HIGHCVSS 8.8v>= 11.0.0, < 11.0.52026-03-11
CVE-2026-22248 [HIGH] CWE-502 CVE-2026-22248: GLPI is an open-source asset and IT management software package that provides ITIL Service Desk feat
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. From 11.0.0 to before 11.0.5, an authenticated technician user can upload a malicious file and trigger its execution through an unsafe PHP instantiation. This vulnerability is fixed in 11.0.5.
nvd
CVE-2026-22247CRITICALCVSS 9.1≥ 11.0.0, < 11.0.5v>= 11.0.0, < 11.0.52026-02-04
CVE-2026-22247 [CRITICAL] CWE-918 CVE-2026-22247: GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLP
GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issue has been patched in version 11.0.5.
nvd
CVE-2026-22044HIGHCVSS 8.8≥ 0.85, < 10.0.23v>= 0.85, < 10.0.232026-02-04
CVE-2026-22044 [HIGH] CWE-89 CVE-2026-22044: GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an aut
GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This issue has been patched in version 10.0.23.
nvd
CVE-2026-23624MEDIUMCVSS 6.5≥ 0.71, < 10.0.23≥ 11.0.0, < 11.0.5+2 more2026-02-04
CVE-2026-23624 [MEDIUM] CWE-384 CVE-2026-23624: GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10
GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO variables, a user can steal a GLPI session previously opened by another user on the same machine. This issue has been patched in versions .
nvd
CVE-2025-66417CRITICALCVSS 9.8≥ 11.0.0, < 11.0.3v>= 11.0.0, < 11.0.32026-01-15
CVE-2025-66417 [CRITICAL] CWE-89 CVE-2025-66417: GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated u
GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.
nvd
CVE-2025-64516HIGHCVSS 7.5≥ 10.0.0, < 10.0.21≥ 11.0.0, < 11.0.3+2 more2026-01-15
CVE-2025-64516 [HIGH] CWE-284 CVE-2025-64516: GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorize
GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthorized access can be performed by an anonymous user. This vulnerability is fixed in 10.0.21 and 11.0.3.
nvd
CVE-2023-53943MEDIUMCVSS 6.9v9.5.72025-12-18
CVE-2023-53943 [MEDIUM] CWE-203 CVE-2023-53943: GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism tha
GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email addresses by submitting requests to the password reset endpoint and analyzing response differences to identify valid user accounts.
nvd
CVE-2025-59935MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.21v>= 10.0.0, < 10.0.212025-12-16
CVE-2025-59935 [MEDIUM] CWE-79 CVE-2025-59935: GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to ver
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inventory endpoint. Users should upgrade to 10.0.21 to receive a patch.
nvd
CVE-2025-64520MEDIUMCVSS 4.3≥ 9.1.0, < 10.0.21v>= 9.1.0, < 10.0.212025-12-16
CVE-2025-64520 [MEDIUM] CWE-862 CVE-2025-64520: GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to vers
GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to 10.0.21 to receive a patch.
nvd
CVE-2025-53105HIGHCVSS 7.5v>= 10.0.0, < 10.0.192025-08-27
CVE-2025-53105 [HIGH] CWE-269 CVE-2025-53105: GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management So
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 10.0.0 to before 10.0.19, a connected user without administration rights can change the rules execution order. This issue has been patched in
nvd
CVE-2025-52897MEDIUMCVSS 6.1≥ 9.1.0, < 10.0.19v>= 9.1.0, < 10.0.192025-07-30
CVE-2025-52897 [MEDIUM] CWE-80 CVE-2025-52897: GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unaut
GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to attempt a phishing attack from the planning feature. This is fixed in version 10.0.19.
nvd
CVE-2025-53357MEDIUMCVSS 5.4≥ 0.78, < 10.0.19v>= 0.78, < 10.0.192025-07-30
CVE-2025-53357 [MEDIUM] CWE-639 CVE-2025-53357: GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management So
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 0.78 through 10.0.18, a connected user can alter the reservations of another user. This is fixed in version 10.0.19.
nvd
CVE-2025-52567MEDIUMCVSS 5.0≥ 0.84, < 10.0.19v>= 0.84, < 10.0.192025-07-30
CVE-2025-52567 [MEDIUM] CWE-918 CVE-2025-52567: GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk,
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 0.84 through 10.0.18, usage of RSS feeds or external calendars when planning is subject to SSRF exploit. The previous security patches provided since GLPI 10.0.4 were not robust enough for certain sp
nvd
1 / 10Next →