Glpi-Project Glpi vulnerabilities
215 known vulnerabilities affecting glpi-project/glpi.
Total CVEs
215
CISA KEV
1
actively exploited
Public exploits
16
Exploited in wild
3
Severity breakdown
CRITICAL28HIGH66MEDIUM118LOW3
Vulnerabilities
Page 9 of 11
CVE-2024-27914P4MEDIUMCVSS 6.1≥ 10.0.8, < 10.0.13v>= 10.0.8, < 10.0.132024-03-18
CVE-2024-27914 [MEDIUM] CWE-79 CVE-2024-27914: GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk,
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS will only trigger if the administrator navigates through the debug bar. This
nvd
CVE-2024-41678P4MEDIUMCVSS 6.1≥ 0.50, < 10.0.17v>= 0.50, < 10.0.172024-11-15
CVE-2024-41678 [MEDIUM] CWE-79 CVE-2024-41678: GLPI is a free asset and IT management software package. An unauthenticated user can provide a malic
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.
nvd
CVE-2024-43418P4MEDIUMCVSS 6.1≥ 0.65, < 10.0.17v>= 0.65, < 10.0.172024-11-15
CVE-2024-43418 [MEDIUM] CWE-79 CVE-2024-43418: GLPI is a free asset and IT management software package. An unauthenticated user can provide a malic
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.
nvd
CVE-2024-43417P4MEDIUMCVSS 6.1≥ 10.0.0, < 10.0.17v>= 10.0.0, < 10.0.172024-11-15
CVE-2024-43417 [MEDIUM] CWE-79 CVE-2024-43417: GLPI is a free asset and IT management software package. An unauthenticated user can provide a malic
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the Software form. Upgrade to 10.0.17.
nvd
CVE-2011-2720P4MEDIUMCVSS 5.0≤ 0.80.1v0.5+31 more2011-08-05
CVE-2011-2720 [MEDIUM] CWE-200 CVE-2011-2720: The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and passw
The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.
nvd
CVE-2022-24869P4MEDIUMCVSS 5.4≤ 0.90v>= 0.90, < 10.0.02022-04-21
CVE-2022-24869 [MEDIUM] CWE-79 CVE-2022-24869: GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, l
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can use ticket's followups or setup login messages with a stylesheet link. This may allow for a cross site scripting attack vector. This issue is partially mitigated by cors securi
nvd
CVE-2020-15217P4MEDIUMCVSS 5.3≥ 9.5.0, < 9.5.2v>= 9.5.0, < 9.5.22020-10-07
CVE-2020-15217 [MEDIUM] CWE-79 CVE-2020-15217: In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The iss
In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in 9.5.2. As a workaround, disable public access to the FAQ.
nvd
CVE-2022-24868P4MEDIUMCVSS 5.4fixed in 10.0.02022-04-21
CVE-2022-24868 [MEDIUM] CWE-79 CVE-2022-24868: GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, l
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can exploit a lack of sanitization on SVG file uploads and inject javascript into their user avatar. As a result any user viewing the avatar will be subject to a cross site scripti
nvd
CVE-2022-31143P4MEDIUMCVSS 5.3fixed in 10.0.3v>=9.5.0, < 10.0.32022-09-14
CVE-2022-31143 [MEDIUM] CWE-200 CVE-2022-31143: GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Softwa
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. It was found that in affected versions there is an exposure of private information defined in setup of GLPI (like smtp or cas hosts). Note that passwords ar
nvd
CVE-2022-39375P4MEDIUMCVSS 5.4≥ 0.84, < 10.0.4v>= 0.84, < 10.0.42022-11-03
CVE-2022-39375 [MEDIUM] CWE-79 CVE-2022-39375: GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Soft
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Users may be able to create a public RSS feed to inject malicious code in dashboards of other users. This issue has been patched, please upgrade to version
nvd
CVE-2022-39372P4MEDIUMCVSS 5.4≥ 0.70, < 10.0.4v>= 0.70, < 10.0.42022-11-03
CVE-2022-39372 [MEDIUM] CWE-79 CVE-2022-39372: GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Soft
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Authenticated users may store malicious code in their account information. This issue has been patched, please upgrade to version 10.0.4. There are currentl
nvd
CVE-2025-27514P4MEDIUMCVSS 5.4≥ 9.5.0, < 10.0.19v>= 9.5.0, < 10.0.192025-07-29
CVE-2025-27514 [MEDIUM] CWE-79 CVE-2025-27514: GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk,
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a technician can use a malicious payload to trigger a stored XSS on the project's kanban. This is fixed in version 10.0.19.
nvd
CVE-2012-4002P4MEDIUMCVSS 6.8≤ 0.83.2v0.5+47 more2012-10-09
CVE-2012-4002 [MEDIUM] CWE-352 CVE-2012-4002: Cross-site request forgery (CSRF) vulnerability in GLPI-PROJECT GLPI before 0.83.3 allows remote att
Cross-site request forgery (CSRF) vulnerability in GLPI-PROJECT GLPI before 0.83.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
nvd
CVE-2020-15226P4MEDIUMCVSS 4.3fixed in 9.5.2v>= 9.1, < 9.5.22020-10-07
CVE-2020-15226 [MEDIUM] CWE-89 CVE-2020-15226: In GLPI before version 9.5.2, there is a SQL Injection in the API's search function. Not only is it
In GLPI before version 9.5.2, there is a SQL Injection in the API's search function. Not only is it possible to break the SQL syntax, but it is also possible to utilise a UNION SELECT query to reflect sensitive information such as the current database version, or database user. The most likely scenario for this vulnerability is with someone who has an
nvd
CVE-2021-21313P4MEDIUMCVSS 6.1fixed in 9.5.42021-03-03
CVE-2021-21313 [MEDIUM] CWE-74 CVE-2021-21313: GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Fr
GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is a vulnerability in the /ajax/common.tabs.php endpoint, indeed, at least two parameters _target and id are not properly sanitized. Here are two payloads (due to two diff
nvd
CVE-2020-15177P4MEDIUMCVSS 6.1fixed in 9.5.2v>= 0.65, < 9.5.22020-10-07
CVE-2020-15177 [MEDIUM] CWE-79 CVE-2020-15177: In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into t
In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_base` and `url_base_api`. These settings are referenced throughout the application and allow for vulnerabilities like Cross-Site Scripting and Insecure Redirection Since authentication is not required to perform these changes,anyone
nvd
CVE-2023-22722P4MEDIUMCVSS 6.1≥ 9.4.0, < 9.5.12≥ 10.0.0, < 10.0.6+1 more2023-01-26
CVE-2023-22722 [MEDIUM] CWE-79 CVE-2023-22722: GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 a
GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 are subject to Cross-site Scripting. An attacker can persuade a victim into opening a URL containing a payload exploiting this vulnerability. After exploited, the attacker can make actions as the victim or exfiltrate session cookies. This issue is patch
nvd
CVE-2019-1010307P4MEDIUMCVSS 5.4v9.3.12019-07-15
CVE-2019-1010307 [MEDIUM] CWE-79 CVE-2019-1010307: GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown valu
GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege escalation and executing js on admin. The component is: /glpi/ajax/getDropDownValue.php. The attack vector is: 1- User Create a ticket , 2- Admin opens another ticket and click on the "Link Tickets" fea
nvd
CVE-2022-24876P4MEDIUMCVSS 5.4v10.0.0fixed in 10.0.12022-06-09
CVE-2022-24876 [MEDIUM] CWE-79 CVE-2022-24876: GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, l
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Kanban is a GLPI view to display Projects, Tickets, Changes or Problems on a task board. In versions prior to 10.0.1 a user can exploit a cross site scripting vulnerability in Kanban by injecting HTML code in its
nvd
CVE-2022-39371P4MEDIUMCVSS 5.4≥ 10.0.0, < 10.0.4v>= 10.0.0, < 10.0.42022-11-03
CVE-2022-39371 [MEDIUM] CWE-80 CVE-2022-39371: GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Soft
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Script related HTML tags in assets inventory information are not properly neutralized. This issue has been patched, please upgrade to version 10.0.4. There
nvd