cbcvebase.

Glpi-Project Glpi vulnerabilities

215 known vulnerabilities affecting glpi-project/glpi.

Total CVEs
215
CISA KEV
1
actively exploited
Public exploits
16
Exploited in wild
3
Severity breakdown
CRITICAL28HIGH66MEDIUM118LOW3

Vulnerabilities

Page 8 of 11
CVE-2026-49469P4MEDIUMCVSS 4.6v>= 0.70, < 10.0.26v>= 11.0.0, < 11.0.82026-09-25
CVE-2026-49469 [MEDIUM] CWE-90 CVE-2026-49469: GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an auth GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter. This allows access to LDAP objects that the default filter was intended to exclude. This issue is fixed in versio
nvd
CVE-2024-23645P4MEDIUMCVSS 6.1≥ 0.65, < 10.0.12v>= 0.65, < 10.0.122024-02-01
CVE-2024-23645 [MEDIUM] CWE-79 CVE-2024-23645: GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. Upgrade to 10.0.12.
nvd
CVE-2012-1104P4MEDIUMCVSS 5.3≥ 0, < 0.84.3+dfsg.1-12019-12-05
CVE-2012-1104 [MEDIUM] CVE-2012-1104: A Security Bypass vulnerability exists in the phpCAS 1 A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.
osv
CVE-2023-53943P4MEDIUMCVSS 5.3v9.5.72025-12-18
CVE-2023-53943 [MEDIUM] CWE-203 CVE-2023-53943: GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism tha GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email addresses by submitting requests to the password reset endpoint and analyzing response differences to identify valid user accounts.
nvd
CVE-2022-35945P4MEDIUMCVSS 6.1fixed in 10.0.3v>= 9.5.0, < 10.0.32022-09-14
CVE-2022-35945 [MEDIUM] CWE-79 CVE-2022-35945: GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Softwa GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Information associated to registration key are not properly escaped in registration key configuration page. They can be used to steal a GLPI administrator co
nvd
CVE-2023-28639P4MEDIUMCVSS 6.1≥ 0.85, < 9.5.13≥ 10.0.0, < 10.0.72023-04-05
CVE-2023-28639 [MEDIUM] CWE-79 CVE-2023-28639: GLPI is a free asset and IT management software package. Starting in version 0.85 and prior to versi GLPI is a free asset and IT management software package. Starting in version 0.85 and prior to versions 9.5.13 and 10.0.7, a malicious link can be crafted by an unauthenticated user. It will be able to exploit a reflected XSS in case any authenticated user opens the crafted link. This issue is fixed in versions 9.5.13 and 10.0.7.
nvd
CVE-2023-34244P4MEDIUMCVSS 6.1≥ 9.4.0, < 10.0.8v>= 9.4.0, < 10.0.82023-07-05
CVE-2023-34244 [MEDIUM] CWE-79 CVE-2023-34244: GLPI is a free asset and IT management software package. Starting in version 9.4.0 and prior to vers GLPI is a free asset and IT management software package. Starting in version 9.4.0 and prior to version 10.0.8, a malicious link can be crafted by an unauthenticated user that can exploit a reflected XSS in case any authenticated user opens the crafted link. Users should upgrade to version 10.0.8 to receive a patch.
nvd
CVE-2025-21627P4MEDIUMCVSS 6.1fixed in 10.0.182025-02-25
CVE-2025-21627 [MEDIUM] CWE-79 CVE-2025-21627: GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious l GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious link can be crafted to perform a reflected XSS attack on the search page. If the anonymous ticket creation is enabled, this attack can be performed by an unauthenticated user. Version 10.0.18 contains a fix for the issue.
nvd
CVE-2024-45610P4MEDIUMCVSS 6.1≥ 10.0.0, < 10.0.17v>= 10.0.0, < 10.0.172024-11-15
CVE-2024-45610 [MEDIUM] CWE-79 CVE-2024-45610: GLPI is an open-source asset and IT management software package that provides ITIL Service Desk feat GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the Cable form. Upgrade to 10.0.17.
nvd
CVE-2024-45609P4MEDIUMCVSS 6.1≥ 0.70, < 10.0.17v>= 0.70, < 10.0.172024-11-15
CVE-2024-45609 [MEDIUM] CWE-79 CVE-2024-45609: GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the reports pages. Upgrade to 10.0.17.
nvd
CVE-2021-21255P4MEDIUMCVSS 5.7v9.5.3v= 9.5.32021-03-02
CVE-2021-21255 [MEDIUM] CWE-862 CVE-2021-21255: GLPI is an open-source asset and IT management software package that provides ITIL Service Desk feat GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in version 9.5.4.
nvd
CVE-2022-31187P4MEDIUMCVSS 5.4fixed in 10.0.3v>= 10.0.0, < 10.0.32022-09-14
CVE-2022-31187 [MEDIUM] CWE-79 CVE-2022-31187: GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Softwa GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Affected versions were found to not properly neutralize HTML tags in the global search context. Users are advised to upgrade to version 10.0.3 to resolve thi
nvd
CVE-2022-31068P4MEDIUMCVSS 5.3≥ 10.0.0, < 10.0.2v>=10.0.0, < 10.0.22022-06-28
CVE-2022-31068 [MEDIUM] CWE-200 CVE-2022-31068: GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all GLPI instances with the native inventory used may leak sensitive information. The feature to get refused file is not authenticated. This issue has been addressed in version 10.0.2 and al
nvd
CVE-2023-41888P4MEDIUMCVSS 5.4≥ 10.0.8, < 10.0.10v>= 10.0.8, < 10.0.102023-09-27
CVE-2023-41888 [MEDIUM] CWE-22 CVE-2023-41888: GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software p GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The lack of path filtering on the GLPI URL may allow an attacker to transmit a malicious URL of login page that can be used to attempt a phishing attack on user
nvd
CVE-2022-39276P4MEDIUMCVSS 5.3fixed in 10.0.42022-11-03
CVE-2022-39276 [MEDIUM] CWE-918 CVE-2022-39276: GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Soft GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Usage of RSS feeds or an external calendar in planning is subject to SSRF exploit. In case a remote script returns a redirect response, the redirect target
nvd
CVE-2024-45611P4MEDIUMCVSS 5.4≥ 0.84, < 10.0.17v>= 0.84, < 10.0.172024-11-15
CVE-2024-45611 [MEDIUM] CWE-79 CVE-2024-45611: GLPI is an open-source asset and IT management software package that provides ITIL Service Desk feat GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can bypass the access control policy to create a private RSS feed attached to another user account and use a malicious payload to triggger a stored XSS. Upgrade to 10.0.17.
nvd
CVE-2022-21720P4MEDIUMCVSS 4.9fixed in 9.5.72022-01-28
CVE-2022-21720 [MEDIUM] CWE-89 CVE-2022-21720: GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administr GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving normally inaccessible data via SQL injection. Version 9.5.7 contains a patch for this issue. As a workaround, disabling the `Entities` update right prevents exploitation of this vulnerability.
nvd
CVE-2025-52567P4MEDIUMCVSS 5.0≥ 0.84, < 10.0.19v>= 0.84, < 10.0.192025-07-30
CVE-2025-52567 [MEDIUM] CWE-918 CVE-2025-52567: GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 0.84 through 10.0.18, usage of RSS feeds or external calendars when planning is subject to SSRF exploit. The previous security patches provided since GLPI 10.0.4 were not robust enough for certain sp
nvd
CVE-2021-3486P4MEDIUMCVSS 6.1v9.5.4vglpi 9.5.42021-05-26
CVE-2021-3486 [MEDIUM] CWE-79 CVE-2021-3486: GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execu GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.
nvd
CVE-2018-7563P4MEDIUMCVSS 6.1≤ 9.2.12018-03-12
CVE-2018-7563 [MEDIUM] CWE-79 CVE-2018-7563: An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query strin An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by the attacker. The attacker-supplied code can perform a wide variety of action
nvd
Glpi-Project Glpi vulnerabilities | cvebase