Glpi-Project Glpi vulnerabilities
215 known vulnerabilities affecting glpi-project/glpi.
Total CVEs
215
CISA KEV
1
actively exploited
Public exploits
16
Exploited in wild
3
Severity breakdown
CRITICAL28HIGH66MEDIUM118LOW3
Vulnerabilities
Page 7 of 11
CVE-2022-39376P3MEDIUMCVSS 6.5≥ 0.65, < 10.0.4v>= 0.65, < 10.0.42022-11-03
CVE-2022-39376 [MEDIUM] CWE-20 CVE-2022-39376: GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Soft
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Users may be able to inject custom fields values in `mailto` links. This issue has been patched, please upgrade to version 10.0.4. There are currently no kn
nvd
CVE-2026-42320P3MEDIUMCVSS 5.9v>= 11.0.0, < 11.0.7v>= 0.50, < 10.0.252026-06-03
CVE-2026-42320 [MEDIUM] CWE-862 CVE-2026-42320: GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versi
GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arbitrary files inside the GLPI_DOC_DIR. Upgrade to 10.0.25 or 11.0.7 to receive a patch.
nvd
CVE-2021-39210P4MEDIUMCVSS 6.5fixed in 9.5.62021-09-15
CVE-2021-39210 [MEDIUM] CWE-1004 CVE-2021-39210: GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would be able to use it to autologin. This issue is fixed in version 9.5.6. As a workaround, one may
nvd
CVE-2026-55217P3MEDIUMCVSS 5.3v>= 0.85, < 10.0.26v>= 11.0.0, < 11.0.82026-09-25
CVE-2026-55217 [MEDIUM] CWE-285 CVE-2026-55217: GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-p
GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations without the required authorization for the affected content. This issue is fixed in versions 11.0.8 and 10.0.26.
nvd
CVE-2026-45801P4MEDIUMCVSS 5.3v>= 0.72, < 10.0.26v>= 11.0.0, < 11.0.82026-09-25
CVE-2026-45801 [MEDIUM] CWE-269 CVE-2026-45801: GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an auth
GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable debug mode. The affected user-setting update does not enforce the privilege boundary intended to restrict debug-mode activation. This issue is fixed in versions 11.0.8 and 10.0.26.
nvd
CVE-2012-1037P4MEDIUMCVSS 6.5v0.78v0.78.1+12 more2012-07-12
CVE-2012-1037 [MEDIUM] CWE-94 CVE-2012-1037: PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remot
PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remote authenticated users to execute arbitrary PHP code via a URL in the sub_type parameter.
nvd
CVE-2025-59935P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.21v>= 10.0.0, < 10.0.212025-12-16
CVE-2025-59935 [MEDIUM] CWE-79 CVE-2025-59935: GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to ver
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inventory endpoint. Users should upgrade to 10.0.21 to receive a patch.
nvd
CVE-2016-7507P4HIGHCVSS 8.0v0.90.42017-07-19
CVE-2016-7507 [HIGH] CWE-352 CVE-2016-7507: Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers
Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creation of an admin account in the application.
nvd
CVE-2026-40108P4HIGHCVSS 7.1v>= 11.0.0, < 11.0.72026-06-02
CVE-2026-40108 [HIGH] CWE-79 CVE-2026-40108: GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a techni
GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. This issue has been fixed in version 11.0.7.
nvd
CVE-2019-13240P4MEDIUMCVSS 5.9fixed in 9.4.12019-07-10
CVE-2019-13240 [MEDIUM] CWE-640 CVE-2019-13240: An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is pos
An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any information except the associated email address.
nvd
CVE-2024-11955P4MEDIUMCVSS 6.1≥ 0.85, < 10.0.18v10.0.0+17 more2025-02-25
CVE-2024-11955 [MEDIUM] CWE-601 CVE-2024-11955: A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by th
A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument redirect leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to vers
nvd
CVE-2025-52897P4MEDIUMCVSS 6.1≥ 9.1.0, < 10.0.19v>= 9.1.0, < 10.0.192025-07-30
CVE-2025-52897 [MEDIUM] CWE-80 CVE-2025-52897: GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unaut
GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to attempt a phishing attack from the planning feature. This is fixed in version 10.0.19.
nvd
CVE-2022-36112P4MEDIUMCVSS 5.8fixed in 10.0.32022-09-14
CVE-2022-36112 [MEDIUM] CWE-918 CVE-2022-36112: GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Softwa
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Usage of RSS feeds or extenal calendar in planning is subject to SSRF exploit. Server-side requests can be used to scan server port or services opened on GL
nvd
CVE-2020-5248P4MEDIUMCVSS 5.3fixed in 9.4.62020-05-12
CVE-2020-5248 [MEDIUM] CWE-798 CVE-2020-5248: GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is
GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means anyone can decrypt sensitive data stored using this key. It is possible to change the key before installing GLPI. But on existing instances, data must be reencrypted with the new key. Problem is we can not
nvd
CVE-2023-28633P4MEDIUMCVSS 5.4≥ 0.84, < 9.5.13≥ 10.0.0, < 10.0.7+2 more2023-04-05
CVE-2023-28633 [MEDIUM] CWE-918 CVE-2023-28633: GLPI is a free asset and IT management software package. Starting in version 0.84 and prior to versi
GLPI is a free asset and IT management software package. Starting in version 0.84 and prior to versions 9.5.13 and 10.0.7, usage of RSS feeds is subject to server-side request forgery (SSRF). In case the remote address is not a valid RSS feed, an RSS autodiscovery feature is triggered. This feature does not check safety or URLs. Versions 9.5.13 and
nvd
CVE-2026-26027P4MEDIUMCVSS 6.1≥ 11.0.0, < 11.0.6v>= 11.0.0, < 11.0.62026-04-06
CVE-2026-26027 [MEDIUM] CWE-79 CVE-2026-26027: GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenti
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6.
nvd
CVE-2024-43416P4MEDIUMCVSS 5.3≥ 0.80, < 10.0.17v>= 0.80, < 10.0.172024-11-18
CVE-2024-43416 [MEDIUM] CWE-200 CVE-2024-43416: GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to versi
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an unauthenticated user can use an application endpoint to check if an email address corresponds to a valid GLPI user. Version 10.0.17 fixes the issue.
nvd
CVE-2023-28849P4MEDIUMCVSS 5.4≥ 10.0.0, < 10.0.7v>= 10.0.0, < 10.0.72023-04-05
CVE-2023-28849 [MEDIUM] CWE-79 CVE-2023-28849: GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to ver
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.7, GLPI inventory endpoint can be used to drive a SQL injection attack. It can also be used to store malicious code that could be used to perform XSS attack. By default, GLPI inventory endpoint requires no authentication. Version 10.0.7 conta
nvd
CVE-2025-53357P4MEDIUMCVSS 5.4≥ 0.78, < 10.0.19v>= 0.78, < 10.0.192025-07-30
CVE-2025-53357 [MEDIUM] CWE-639 CVE-2025-53357: GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management So
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 0.78 through 10.0.18, a connected user can alter the reservations of another user. This is fixed in version 10.0.19.
nvd
CVE-2017-11183P4MEDIUMCVSS 4.9≤ 9.1.42017-07-28
CVE-2017-11183 [MEDIUM] CWE-20 CVE-2017-11183: front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary
front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.
nvd