mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vulnerability is fixed in 1.9.4.
References
Configurations
History
20 Feb 2026, 18:20
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/pluginsGLPI/mreporting/commit/6f4a3caf9c1f7bbed1d910795d6e918d039f1f72 - Patch | |
| References | () https://github.com/pluginsGLPI/mreporting/security/advisories/GHSA-24q7-h59q-33w8 - Vendor Advisory | |
| CPE | cpe:2.3:a:glpi-project:more_reporting:*:*:*:*:*:glpi:*:* | |
| Summary |
|
|
| First Time |
Glpi-project more Reporting
Glpi-project |
12 Feb 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-12 19:15
Updated : 2026-02-20 18:20
NVD link : CVE-2026-22821
Mitre link : CVE-2026-22821
CVE.ORG link : CVE-2026-22821
JSON object : View
Products Affected
glpi-project
- more_reporting
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
