Teclib-Edition Glpi vulnerabilities
3 known vulnerabilities affecting teclib-edition/glpi.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-25937MEDIUMCVSS 6.5≥ 11.0.0, < 11.0.62026-03-18
CVE-2026-25937 [MEDIUM] CWE-287 CVE-2026-25937: GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to ver
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor with knowledge of a user's credentials can bypass MFA and steal their account. Version 11.0.6 fixes the issue.
nvd
CVE-2026-25936HIGHCVSS 8.8≤ 11.0.62026-03-17
CVE-2026-25936 [HIGH] CWE-89 CVE-2026-25936: GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to ver
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injection. Version 11.0.6 fixes the issue.
nvd
CVE-2026-22248HIGHCVSS 8.8≥ 11.0.0, < 11.0.52026-03-11
CVE-2026-22248 [HIGH] CWE-502 CVE-2026-22248: GLPI is an open-source asset and IT management software package that provides ITIL Service Desk feat
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. From 11.0.0 to before 11.0.5, an authenticated technician user can upload a malicious file and trigger its execution through an unsafe PHP instantiation. This vulnerability is fixed in 11.0.5.
nvd