Glpi-Project Glpi vulnerabilities
193 known vulnerabilities affecting glpi-project/glpi.
Total CVEs
193
CISA KEV
1
actively exploited
Public exploits
15
Exploited in wild
1
Severity breakdown
CRITICAL27HIGH53MEDIUM111LOW2
Vulnerabilities
Page 2 of 10
CVE-2025-53111MEDIUMCVSS 6.5≥ 0.80, < 10.0.19v>= 0.80, < 10.0.192025-07-30
CVE-2025-53111 [MEDIUM] CWE-284 CVE-2025-53111: GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of
GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized access to some resources. This is fixed in version 10.0.19.
nvd
CVE-2025-53008MEDIUMCVSS 6.5≥ 9.3.1, < 10.0.19v>= 9.3.1, < 10.0.192025-07-30
CVE-2025-53008 [MEDIUM] CWE-522 CVE-2025-53008: GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software p
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.3.1 through 10.0.19, a connected user can use a malicious payload to steal mail receiver credentials. This is fixed in version 10.0.19.
nvd
CVE-2025-53112MEDIUMCVSS 4.3≥ 9.1.0, < 10.0.19v>= 9.1.0, < 10.0.192025-07-30
CVE-2025-53112 [MEDIUM] CWE-284 CVE-2025-53112: GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, l
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.1.0 through 10.0.18, a lack of permission checks can result in unauthorized removal of some specific resources. This is fixed in version 10.0.19.
nvd
CVE-2025-53113LOWCVSS 2.7≥ 0.65, < 10.0.19v>= 0.65, < 10.0.192025-07-30
CVE-2025-53113 [LOW] CWE-284 CVE-2025-53113: GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management So
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 0.65 through 10.0.18, a technician can use the external links feature to fetch information on items they do not have the right to see. This is
nvd
CVE-2025-27514MEDIUMCVSS 5.4≥ 9.5.0, < 10.0.19v>= 9.5.0, < 10.0.192025-07-29
CVE-2025-27514 [MEDIUM] CWE-79 CVE-2025-27514: GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk,
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a technician can use a malicious payload to trigger a stored XSS on the project's kanban. This is fixed in version 10.0.19.
nvd
CVE-2025-24799CRITICALCVSS 9.8PoC≥ 10.0.0, < 10.0.18v>= 10.0.0, < 10.0.182025-03-18
CVE-2025-24799 [CRITICAL] CWE-89 CVE-2025-24799: GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL i
GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.
nvd
CVE-2025-24801HIGHCVSS 8.8≥ 0.85, < 10.0.18v>= 0.85, < 10.0.182025-03-18
CVE-2025-24801 [HIGH] CWE-434 CVE-2025-24801: GLPI is a free asset and IT management software package. An authenticated user can upload and force
GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18.
nvd
CVE-2025-21619HIGHCVSS 8.2≥ 0.78, < 10.0.18v>= 0.78, < 10.0.182025-03-18
CVE-2025-21619 [HIGH] CWE-89 CVE-2025-21619: GLPI is a free asset and IT management software package. An administrator user can perfom a SQL inje
GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This vulnerability is fixed in 10.0.18.
nvd
CVE-2025-25192MEDIUMCVSS 6.5fixed in 10.0.182025-02-25
CVE-2025-25192 [MEDIUM] CWE-200 CVE-2025-25192: GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged
GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive information. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` file.
nvd
CVE-2025-21627MEDIUMCVSS 6.1fixed in 10.0.182025-02-25
CVE-2025-21627 [MEDIUM] CWE-79 CVE-2025-21627: GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious l
GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious link can be crafted to perform a reflected XSS attack on the search page. If the anonymous ticket creation is enabled, this attack can be performed by an unauthenticated user. Version 10.0.18 contains a fix for the issue.
nvd
CVE-2025-21626MEDIUMCVSS 6.5≥ 0.71, < 10.0.18v>= 0.71, < 10.0.182025-02-25
CVE-2025-21626 [MEDIUM] CWE-200 CVE-2025-21626: GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to versi
GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive information from the `status.php` endpoint. Version 10.0.18 contains a fix for the issue. Some workarounds are available. One may delete the `status.php` file, restrict its access, or remove any sensit
nvd
CVE-2024-11955MEDIUMCVSS 5.3≥ 0.85, < 10.0.18v10.0.0+17 more2025-02-25
CVE-2024-11955 [MEDIUM] CWE-601 CVE-2024-11955: A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by th
A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument redirect leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to vers
nvd
CVE-2025-23024MEDIUMCVSS 6.9≥ 0.72, < 10.0.18v>= 0.72, < 10.0.182025-02-25
CVE-2025-23024 [MEDIUM] CWE-285 CVE-2025-23024: GLPI is a free asset and IT management software package. Starting in version 0.72 and prior to versi
GLPI is a free asset and IT management software package. Starting in version 0.72 and prior to version 10.0.18, an anonymous user can disable all the active plugins. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` file.
nvd
CVE-2025-23046MEDIUMCVSS 6.3≥ 9.5.0, < 10.0.18v>= 9.5.0, < 10.0.182025-02-25
CVE-2025-23046 [MEDIUM] CWE-303 CVE-2025-23046: GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to vers
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.18, if a "Mail servers" authentication provider is configured to use an Oauth connection provided by the OauthIMAP plugin, anyone can connect to GLPI using a user name on which an Oauth authorization has already been established. Version 10.0
nvd
CVE-2024-50339CRITICALCVSS 9.3≥ 9.5.0, < 10.0.17v>= 9.5.0, < 10.0.172024-12-12
CVE-2024-50339 [CRITICAL] CWE-79 CVE-2024-50339: GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to vers
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version 10.0.17 contains a patch for this issue.
nvd
CVE-2024-47761HIGHCVSS 7.5≥ 0.80, < 10.0.17v>= 0.80, < 10.0.172024-12-11
CVE-2024-47761 [HIGH] CWE-287 CVE-2024-47761: GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to versi
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an administrator with access to the sent notifications contents can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.
nvd
CVE-2024-47758HIGHCVSS 7.6≥ 9.3.0, < 10.0.17v>= 9.3.0, < 10.0.172024-12-11
CVE-2024-47758 [HIGH] CWE-284 CVE-2024-47758: GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to vers
GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the API to take control of any user that have the same or a lower level of privileges. Version 10.0.17 contains a patch for this issue.
nvd
CVE-2024-47760HIGHCVSS 7.5≥ 9.1.0, < 10.0.17v>= 9.1.0, < 10.0.172024-12-11
CVE-2024-47760 [HIGH] CWE-284 CVE-2024-47760: GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to vers
GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with an access to the API can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.
nvd
CVE-2024-48912HIGHCVSS 7.2≥ 10.0.0, < 10.0.17v>= 10.0.0, < 10.0.172024-12-11
CVE-2024-48912 [HIGH] CWE-284 CVE-2024-48912: GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to ver
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated user can use an application endpoint to delete any user account. Version 10.0.17 contains a patch for this issue.
nvd
CVE-2024-43416MEDIUMCVSS 5.3≥ 0.80, < 10.0.17v>= 0.80, < 10.0.172024-11-18
CVE-2024-43416 [MEDIUM] CWE-200 CVE-2024-43416: GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to versi
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an unauthenticated user can use an application endpoint to check if an email address corresponds to a valid GLPI user. Version 10.0.17 fixes the issue.
nvd