Filtered by vendor Glpi-project
Subscribe
Total
200 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2012-4003 | 1 Glpi-project | 1 Glpi | 2026-04-29 | 4.3 MEDIUM | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in GLPI-PROJECT GLPI before 0.83.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors. | |||||
| CVE-2013-5696 | 1 Glpi-project | 1 Glpi | 2026-04-29 | 6.8 MEDIUM | N/A |
| inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection via an Etape_4 action or (2) execute arbitrary PHP code via an update_1 action. | |||||
| CVE-2011-2720 | 1 Glpi-project | 1 Glpi | 2026-04-29 | 5.0 MEDIUM | N/A |
| The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request. | |||||
| CVE-2012-1037 | 1 Glpi-project | 1 Glpi | 2026-04-29 | 6.5 MEDIUM | N/A |
| PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remote authenticated users to execute arbitrary PHP code via a URL in the sub_type parameter. | |||||
| CVE-2012-4002 | 1 Glpi-project | 1 Glpi | 2026-04-29 | 6.8 MEDIUM | N/A |
| Cross-site request forgery (CSRF) vulnerability in GLPI-PROJECT GLPI before 0.83.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |||||
| CVE-2026-25932 | 1 Glpi-project | 1 Glpi | 2026-04-07 | N/A | 7.2 HIGH |
| GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24. | |||||
| CVE-2026-26026 | 1 Glpi-project | 1 Glpi | 2026-04-07 | N/A | 9.1 CRITICAL |
| GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6. | |||||
| CVE-2026-26027 | 1 Glpi-project | 1 Glpi | 2026-04-07 | N/A | 7.5 HIGH |
| GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6. | |||||
| CVE-2026-26263 | 1 Glpi-project | 1 Glpi | 2026-04-07 | N/A | 8.1 HIGH |
| GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6. | |||||
| CVE-2026-29047 | 1 Glpi-project | 1 Glpi | 2026-04-07 | N/A | 7.2 HIGH |
| GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the logs export feature. This vulnerability is fixed in 10.0.24 and 11.0.6. | |||||
| CVE-2026-26001 | 1 Glpi-project | 1 Glpi Inventory | 2026-03-23 | N/A | 7.1 HIGH |
| The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, non sanitized user input can lend to an SQL injection from reports, with adequate rights. This vulnerability is fixed in 1.6.6. | |||||
| CVE-2026-25590 | 1 Glpi-project | 1 Glpi Inventory | 2026-03-05 | N/A | 4.5 MEDIUM |
| The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, there is a reflected XSS vulnerability in task jobs. This vulnerability is fixed in 1.6.6. | |||||
| CVE-2026-22821 | 1 Glpi-project | 1 More Reporting | 2026-02-20 | N/A | 4.9 MEDIUM |
| mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vulnerability is fixed in 1.9.4. | |||||
| CVE-2025-64520 | 1 Glpi-project | 1 Glpi | 2026-02-19 | N/A | 6.5 MEDIUM |
| GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to 10.0.21 to receive a patch. | |||||
| CVE-2026-22044 | 1 Glpi-project | 1 Glpi | 2026-02-06 | N/A | 6.5 MEDIUM |
| GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This issue has been patched in version 10.0.23. | |||||
| CVE-2026-22247 | 1 Glpi-project | 1 Glpi | 2026-02-06 | N/A | 4.1 MEDIUM |
| GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issue has been patched in version 11.0.5. | |||||
| CVE-2026-23624 | 1 Glpi-project | 1 Glpi | 2026-02-06 | N/A | 4.3 MEDIUM |
| GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO variables, a user can steal a GLPI session previously opened by another user on the same machine. This issue has been patched in versions . | |||||
| CVE-2025-59935 | 1 Glpi-project | 1 Glpi | 2026-02-02 | N/A | 6.5 MEDIUM |
| GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inventory endpoint. Users should upgrade to 10.0.21 to receive a patch. | |||||
| CVE-2025-66417 | 1 Glpi-project | 1 Glpi | 2026-01-21 | N/A | 7.5 HIGH |
| GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3. | |||||
| CVE-2025-64516 | 1 Glpi-project | 1 Glpi | 2026-01-21 | N/A | 7.5 HIGH |
| GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthorized access can be performed by an anonymous user. This vulnerability is fixed in 10.0.21 and 11.0.3. | |||||
