Glpi-Project Glpi vulnerabilities
215 known vulnerabilities affecting glpi-project/glpi.
Total CVEs
215
CISA KEV
1
actively exploited
Public exploits
16
Exploited in wild
3
Severity breakdown
CRITICAL28HIGH66MEDIUM118LOW3
Vulnerabilities
Page 6 of 11
CVE-2026-44281P3HIGHCVSS 7.0v>= 11.0.0, < 11.0.7v>= 0.78, < 10.0.252026-06-03
CVE-2026-44281 [HIGH] CWE-862 CVE-2026-44281: GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versi
GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user with config READ permission can read a specific asset object. Upgrade to 11.0.7 or 10.0.25 to receive a patch.
nvd
CVE-2023-23610P3MEDIUMCVSS 6.5≥ 0.65, < 9.5.12≥ 10.0.0, < 10.0.6+2 more2023-01-26
CVE-2023-23610 [MEDIUM] CWE-269 CVE-2023-23610: GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vul
GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, even those on which user is not allowed to access (including assets, tickets, users, ...). This issue is patched i
nvd
CVE-2019-10233P3HIGHCVSS 8.1fixed in 9.4.1.12019-03-27
CVE-2019-10233 [HIGH] CWE-203 CVE-2019-10233: Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.
Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.
nvd
CVE-2026-53627P3MEDIUMCVSS 6.0v>= 11.0.0, < 11.0.82026-09-25
CVE-2026-53627 [MEDIUM] CWE-862 CVE-2026-53627: GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that the same user is normally forbidden to perform through the user interface. The API update flow does not consistently enforce the applicable authorization checks. This issue i
nvd
CVE-2026-53610P3HIGHCVSS 7.5v>= 11.0.0, < 11.0.82026-09-25
CVE-2026-53610 [HIGH] CWE-79 CVE-2026-53610: GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can c
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without sufficient output encoding. A user who opens the crafted URL triggers reflected cross-site scripting in the dashboard. This issue is fixed in version 11.0.8.
nvd
CVE-2022-35946P3MEDIUMCVSS 6.5fixed in 10.0.3v>= 0.72, < 10.0.32022-09-14
CVE-2022-35946 [MEDIUM] CWE-89 CVE-2022-35946: GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Softwa
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In affected versions request input is not properly validated in the plugin controller and can be used to access low-level API of Plugin class. An attacker ca
nvd
CVE-2026-53628P3MEDIUMCVSS 5.9v>= 0.84, < 10.0.26v>= 11.0.0, < 11.0.82026-09-25
CVE-2026-53628 [MEDIUM] CWE-285 CVE-2026-53628: GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an admi
GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right can change the authentication method and disable two-factor authentication for user accounts outside the administrator's entity scope. The affected user-account administrati
nvd
CVE-2024-27937P4MEDIUMCVSS 4.3≥ 10.0.0, < 10.0.13v>= 10.0.0, < 10.0.132024-03-18
CVE-2024-27937 [MEDIUM] CWE-285 CVE-2024-27937: GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk,
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can obtain the email address of all GLPI users. This issue has been patched in version 10.0.13.
nvd
CVE-2023-34106P3MEDIUMCVSS 6.5≥ 0.68, < 10.0.8v>= 0.68, < 10.0.82023-07-05
CVE-2023-34106 [MEDIUM] CWE-284 CVE-2023-34106: GLPI is a free asset and IT management software package. Versions of the software starting with 0.68
GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user. This allows access to the list of all users and their personal information. Users should upgrade to version 10.0.8 to receive a patch.
nvd
CVE-2023-34107P3MEDIUMCVSS 6.5≥ 9.2.0, < 10.0.8v>= 9.2.0, < 10.0.82023-07-05
CVE-2023-34107 [MEDIUM] CWE-284 CVE-2023-34107: GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.
GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user, allows access to the view all KnowbaseItems. Version 10.0.8 has a patch for this issue.
nvd
CVE-2025-21626P3MEDIUMCVSS 6.5≥ 0.71, < 10.0.18v>= 0.71, < 10.0.182025-02-25
CVE-2025-21626 [MEDIUM] CWE-200 CVE-2025-21626: GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to versi
GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive information from the `status.php` endpoint. Version 10.0.18 contains a fix for the issue. Some workarounds are available. One may delete the `status.php` file, restrict its access, or remove any sensit
nvd
CVE-2021-21324P3MEDIUMCVSS 6.5fixed in 9.5.42021-03-08
CVE-2021-21324 [MEDIUM] CWE-639 CVE-2021-21324: GLPI is an open-source asset and IT management software package that provides ITIL Service Desk feat
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 there is an Insecure Direct Object Reference (IDOR) on "Solutions". This vulnerability gives an unauthorized user the ability to enumerate GLPI items names (including users lo
nvd
CVE-2024-27930P3MEDIUMCVSS 6.5≥ 0.78, < 10.0.13v>= 0.78, < 10.0.132024-03-18
CVE-2024-27930 [MEDIUM] CWE-285 CVE-2024-27930: GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk,
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can access sensitive fields data from items on which he has read access. This issue has been patched in version 10.0.13.
nvd
CVE-2023-41321P3MEDIUMCVSS 6.5≥ 9.1.1, < 10.0.10v>= 9.1.1, < 10.0.102023-09-27
CVE-2023-41321 [MEDIUM] CWE-200 CVE-2023-41321: GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software p
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. An API user can enumerate sensitive fields values on resources on which he has read access. Users are advised to upgrade to version 10.0.10. There are no known
nvd
CVE-2022-29250P3MEDIUMCVSS 6.5v10.0.0fixed in 10.0.12022-06-09
CVE-2022-29250 [MEDIUM] CWE-89 CVE-2022-29250: GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, l
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to version 10.0.1 it is possible to add extra information by SQL injection on search pages. In order to exploit this vulnerability a user must be logged in.
nvd
CVE-2025-25192P3MEDIUMCVSS 6.5fixed in 10.0.182025-02-25
CVE-2025-25192 [MEDIUM] CWE-200 CVE-2025-25192: GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged
GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive information. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` file.
nvd
CVE-2025-53111P3MEDIUMCVSS 6.5≥ 0.80, < 10.0.19v>= 0.80, < 10.0.192025-07-30
CVE-2025-53111 [MEDIUM] CWE-284 CVE-2025-53111: GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of
GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized access to some resources. This is fixed in version 10.0.19.
nvd
CVE-2025-53008P3MEDIUMCVSS 6.5≥ 9.3.1, < 10.0.19v>= 9.3.1, < 10.0.192025-07-30
CVE-2025-53008 [MEDIUM] CWE-522 CVE-2025-53008: GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software p
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.3.1 through 10.0.19, a connected user can use a malicious payload to steal mail receiver credentials. This is fixed in version 10.0.19.
nvd
CVE-2021-21326P3MEDIUMCVSS 6.5fixed in 9.5.42021-03-08
CVE-2021-21326 [MEDIUM] CWE-862 CVE-2021-21326: GLPI is an open-source asset and IT management software package that provides ITIL Service Desk feat
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 it is possible to create tickets for another user with self-service interface without delegatee systems enabled. This is fixed in version 9.5.4.
nvd
CVE-2020-26212P3MEDIUMCVSS 6.5fixed in 9.5.32020-11-25
CVE-2020-26212 [MEDIUM] CWE-862 CVE-2020-26212: GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Sof
GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.3, any authenticated user has read-only permissions to the planning of every other user, even admin ones. Steps to reproduce t
nvd