Product
glpi project glpi
191 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-32312
CVE-2026-29047
CVE-2026-26263
CVE-2026-26027
CVE-2026-26026
CVE-2026-25932
CVE-2026-25937
CVE-2026-25936
CVE-2026-22248
CVE-2026-23624
CVE-2026-22247
CVE-2026-22044
CVE-2025-66417
CVE-2025-64516
CVE-2023-53943
CVE-2025-64520
CVE-2025-59935
CVE-2025-53357
CVE-2025-53113
CVE-2025-53112
CVE-2025-53111
CVE-2025-53008
CVE-2025-52897
CVE-2025-52567
CVE-2025-27514
CVE-2025-24801
CVE-2025-24799
CVE-2025-21619
CVE-2025-25192
CVE-2025-23046
CVE-2025-23024
CVE-2025-21627
CVE-2025-21626
CVE-2024-11955
CVE-2024-50339
CVE-2024-48912
CVE-2024-47761
CVE-2024-47760
CVE-2024-47758
CVE-2024-43416
CVE-2024-38370
CVE-2024-45611
CVE-2024-45610
CVE-2024-45609
CVE-2024-45608
CVE-2024-43418
CVE-2024-43417
CVE-2024-41679
CVE-2024-47759
CVE-2024-41678
CVE-2024-40638
CVE-2024-37149
CVE-2024-37148
CVE-2024-37147
CVE-2024-31456
CVE-2024-29889
CVE-2024-27914
CVE-2024-27104
CVE-2024-27098
CVE-2024-27096
CVE-2024-27937
CVE-2024-27930
CVE-2024-27756
CVE-2024-23645
CVE-2023-51446
CVE-2023-46727
CVE-2023-46726
CVE-2023-43813
CVE-2023-42802
CVE-2023-42462
CVE-2023-42461
CVE-2023-41888
CVE-2023-41326
CVE-2023-41324
CVE-2023-41323
CVE-2023-41322
CVE-2023-41321
CVE-2023-41320
CVE-2023-37278
CVE-2023-36808
CVE-2023-35940
CVE-2023-35939
CVE-2023-35924
CVE-2023-34244
CVE-2023-34107
CVE-2023-34106
CVE-2023-28852
CVE-2023-28849
CVE-2023-28838
CVE-2023-28639
CVE-2023-28636
CVE-2023-28634
CVE-2023-28633
CVE-2023-28632
CVE-2023-23610
CVE-2023-22725
CVE-2023-22724
CVE-2023-22722
CVE-2023-22500
CVE-2022-41941
CVE-2022-39376
CVE-2022-39375
CVE-2022-39373
CVE-2022-39372
CVE-2022-39371
CVE-2022-39370
CVE-2022-39277
CVE-2022-39323
CVE-2022-39276
CVE-2022-39262
CVE-2022-39234
CVE-2022-35914
CVE-2022-36112
CVE-2022-35947
CVE-2022-35946
CVE-2022-35945
CVE-2022-31187
CVE-2022-31143
CVE-2022-31068
CVE-2022-31061
CVE-2022-31056
CVE-2022-29250
CVE-2022-24876
CVE-2022-24869
CVE-2022-24868
CVE-2022-24867
CVE-2021-44617
CVE-2022-21720
CVE-2022-21719
CVE-2021-39213
CVE-2021-39211
CVE-2021-39210
CVE-2021-39209
CVE-2021-3486
CVE-2021-21327
CVE-2021-21326
CVE-2021-21325
CVE-2021-21324
CVE-2021-21314
CVE-2021-21313
CVE-2021-21312
CVE-2021-21258
CVE-2021-21255
CVE-2020-27663
CVE-2020-27662
CVE-2020-26212
CVE-2020-15226
CVE-2020-15217
CVE-2020-15177
CVE-2020-15176
CVE-2020-15175
CVE-2020-11031
CVE-2020-15108
CVE-2020-11062
CVE-2020-11060
CVE-2020-5248
CVE-2020-11036
CVE-2020-11035
CVE-2020-11034
CVE-2020-11033
CVE-2020-11032
CVE-2013-2227
CVE-2019-14666
CVE-2019-1010307
CVE-2019-1010310
CVE-2019-13240
CVE-2019-13239
CVE-2019-10233
CVE-2018-13049
CVE-2018-7563
CVE-2018-7562
CVE-2017-11184
CVE-2017-11183
CVE-2017-11475
CVE-2017-11474
CVE-2016-7509
CVE-2016-7507
CVE-2017-11329
CVE-2016-7508
CVE-2015-7685
CVE-2015-7684
CVE-2014-8360
CVE-2014-5032
CVE-2014-9258
CVE-2013-2225
CVE-2013-2226
CVE-2013-5696
CVE-2012-4003
CVE-2012-4002
CVE-2012-1037
CVE-2011-2720
>= 11.0.0 and < 11.0.7
GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ
>= 10.0.0 and < 10.0.24
GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perfo
>= 11.0.0 and < 11.0.6
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL inj
>= 11.0.0 and < 11.0.6
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS pa
>= 11.0.0 and < 11.0.6
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead
>= 0.60 and < 10.0.24
GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store a
>= 11.0.0 and < 11.0.6
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor
> 11.0.0 and <= 11.0.6
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated
>= 11.0.0 and < 11.0.5
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and so
>= 0.71 and < 10.0.23
GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when
>= 11.0.0 and < 11.0.5
GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SS
>= 0.85 and < 10.0.23
GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a
>= 11.0.0 and < 11.0.3
GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injectio
>= 10.0.0 and < 10.0.21
GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documen
all versions
GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate
>= 9.1.0 and < 10.0.21
GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized u
>= 10.0.0 and < 10.0.21
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticat
>= 0.78 and < 10.0.19
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides
>= 0.65 and < 10.0.19
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides
>= 9.1.0 and < 10.0.19
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software
>= 0.80 and < 10.0.19
GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result
>= 9.3.1 and < 10.0.19
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Ser
>= 9.1.0 and < 10.0.19
GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a mal
>= 0.84 and < 10.0.19
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software
>= 9.5.0 and < 10.0.19
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software
>= 0.85 and < 10.0.18
GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files l
>= 10.0.0 and < 10.0.18
GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory
>= 0.78 and < 10.0.18
GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules config
< 10.0.18
GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and
>= 9.5.0 and < 10.0.18
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.18, if a "Mail server
>= 0.72 and < 10.0.18
GLPI is a free asset and IT management software package. Starting in version 0.72 and prior to version 10.0.18, an anonymous user
< 10.0.18
GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious link can be crafted to perform
>= 0.71 and < 10.0.18
GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user
>= 0.85 and < 10.0.18
A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is an unknown
>= 9.5.0 and < 10.0.17
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticate
>= 10.0.0 and < 10.0.17
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated
>= 0.80 and < 10.0.17
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an administrator w
>= 9.1.0 and < 10.0.17
GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with
>= 9.3.0 and < 10.0.17
GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated
>= 0.80 and < 10.0.17
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an unauthenticated
>= 9.2.0 and < 10.0.16
GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a docum
>= 0.84 and < 10.0.17
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and so
>= 10.0.0 and < 10.0.17
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and so
>= 0.70 and < 10.0.17
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software
>= 9.5.0 and < 10.0.17
GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing its preferen
>= 0.65 and < 10.0.17
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician
>= 10.0.0 and < 10.0.17
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician
>= 10.0.0 and < 10.0.17
GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability from the
>= 9.2.0 and < 10.0.17
GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. The script
>= 0.50 and < 10.0.17
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician
>= 0.85 and < 10.0.17
GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities.
>= 0.85 and < 10.0.16
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and so
>= 0.84 and < 10.0.16
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and so
>= 0.85 and < 10.0.16
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and so
>= 9.3.0 and < 10.0.15
GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulne
>= 10.0.10 and < 10.0.15
GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulne
>= 10.0.8 and < 10.0.13
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software
>= 9.5.0 and < 10.0.13
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software
>= 9.5.0 and < 10.0.13
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software
>= 0.65 and < 10.0.13
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software
>= 10.0.0 and < 10.0.13
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software
>= 0.78 and < 10.0.13
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software
<= 10.0.12
GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.
>= 0.65 and < 10.0.12
GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. Upgrade to
>= 0.70 and < 10.0.12
GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication form can b
>= 10.0.0 and < 10.0.11
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory e
>= 10.0.0 and < 10.0.11
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only,
>= 10.0.0 and < 10.0.11
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, the saved search
>= 10.0.7 and < 10.0.10
GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified ob
>= 10.0.0 and < 10.0.10
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Ser
>= 10.0.0 and < 10.0.10
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Ser
>= 10.0.8 and < 10.0.10
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Ser
>= 9.5.0 and < 10.0.10
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Ser
>= 9.3.0 and < 10.0.10
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Ser
>= 0.68 and < 10.0.10
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Ser
>= 9.1.0 and < 10.0.10
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Ser
>= 9.1.1 and < 10.0.10
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Ser
>= 10.0.0 and < 10.0.10
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Ser
< 10.0.9
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software
>= 0.80 and < 10.0.8
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Ma
>= 9.5.0 and < 10.0.8
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect right
>= 9.5.0 and < 10.0.8
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect right
>= 10.0.0 and < 10.0.8
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory en
>= 9.4.0 and < 10.0.8
GLPI is a free asset and IT management software package. Starting in version 9.4.0 and prior to version 10.0.8, a malicious link c
>= 9.2.0 and < 10.0.8
GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an
>= 0.68 and < 10.0.8
GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an i
>= 9.5.0 and < 9.5.13
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 9.5.13 and 10.0.7, a user
>= 10.0.0 and < 10.0.7
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.7, GLPI inventory en
>= 0.50 and < 9.5.13
GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 9.5.13 and 10.0.7, a SQL I
>= 0.85 and < 9.5.13
GLPI is a free asset and IT management software package. Starting in version 0.85 and prior to versions 9.5.13 and 10.0.7, a malic
>= 0.60 and < 9.5.13
GLPI is a free asset and IT management software package. Starting in version 0.60 and prior to versions 9.5.13 and 10.0.7, a vulne
>= 0.83 and < 9.5.13
GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, a user
>= 0.84 and < 9.5.13
GLPI is a free asset and IT management software package. Starting in version 0.84 and prior to versions 9.5.13 and 10.0.7, usage o
>= 0.83 and < 9.5.13
GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, an auth
>= 0.65 and < 9.5.12
GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege
>= 0.60 and < 9.5.12
GLPI is a Free Asset and IT Management Software package. Versions 0.6.0 and above, prior to 10.0.6 are vulnerable to Cross-site Sc
>= 10.0.0 and < 10.0.6
GLPI is a Free Asset and IT Management Software package. Versions prior to 10.0.6 are subject to Cross-site Scripting via maliciou
>= 9.4.0 and < 9.5.12
GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 are subject to Cross-site Scrip
>= 10.0.0 and < 10.0.6
GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6 are vulnerable to Incorrect Au
>= 0.70 and < 9.5.12
GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6, are subject to Cross-site Scr
>= 0.65 and < 10.0.4
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITI
>= 0.84 and < 10.0.4
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITI
>= 10.0.0 and < 10.0.4
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITI
>= 0.70 and < 10.0.4
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITI
>= 10.0.0 and < 10.0.4
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITI
>= 0.70 and < 10.0.4
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITI
>= 0.60 and < 10.0.4
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITI
>= 9.1 and < 10.0.4
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITI
< 10.0.4
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITI
>= 0.65 and < 10.0.4
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package, GLPI administrat
< 10.0.4
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITI
<= 10.0.2
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
< 10.0.3
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL
< 10.0.3
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL
< 10.0.3
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL
< 10.0.3
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL
< 10.0.3
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL
< 10.0.3
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL
>= 10.0.0 and < 10.0.2
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software
>= 9.3.0 and < 9.5.8
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software
>= 10.0.0 and < 10.0.2
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software
all versions
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software
all versions
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software
<= 0.90
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software
< 10.0.0
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software
< 10.0.0
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software
all versions
A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOut
< 9.5.7
GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving
< 9.5.7
GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cross-site s
>= 9.1 and < 9.5.6
GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest en
>= 9.2 and < 9.5.6
GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoin
< 9.5.6
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie
< 9.5.6
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cr
all versions
GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.
< 9.5.4
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and so
< 9.5.4
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and so
< 9.5.4
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and so
< 9.5.4
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and so
< 9.5.4
GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Sof
< 9.5.4
GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Sof
< 9.5.4
GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Sof
>= 9.5.0 and < 9.5.4
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and so
all versions
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and so
< 9.5.3
In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attack
< 9.5.3
In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to re
< 9.5.3
GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides I
< 9.5.2
In GLPI before version 9.5.2, there is a SQL Injection in the API's search function. Not only is it possible to break the SQL synt
>= 9.5.0 and < 9.5.2
In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9
< 9.5.2
In GLPI before version 9.5.2, the
install/install.php endpoint insecurely stores user input into the database as url_base and< 9.5.2
In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape o
< 9.5.2
In GLPI before version 9.5.2, the
pluginimage.send.php endpoint allows a user to specify an image from a plugin. The param< 9.5.0
In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password
< 9.5.1
In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1.
>= 0.68.1 and < 9.4.6
In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has
< 9.4.6
In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerabili
< 9.4.6
GLPI before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every in
< 9.4.6
In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored XSS in the
>= 0.83.3 and < 9.4.6
In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementati
< 9.4.6
In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on
>= 9.1 and < 9.4.6
In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of
all versions
In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability req
all versions
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
<= 9.4.3
GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct
all versions
GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leadi
all versions
GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder d
< 9.4.1
An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's pa
>= 9.1 and < 9.4.3
inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.
< 9.4.1.1
Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.
>= 9.2.0 and <= 9.3.0
The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by triggering
<= 9.2.1
An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An
<= 9.2.1
A remote code execution issue was discovered in GLPI through 9.2.1. There is a race condition that allows temporary access to an u
<= 9.1.4
SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.
<= 9.1.4
front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file para
<= 9.1.5.0
GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.
<= 9.1.5.0
GLPI before 9.1.5.1 has SQL Injection in the $crit variable in inc/computer_softwareversion.class.php, exploitable via ajax/common
all versions
Cross-site scripting (XSS) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to inject arbitrary web script or HT
all versions
Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that coul
<= 9.1.4
GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a li
all versions
Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by
<= 0.85.2
GLPI before 0.85.3 allows remote authenticated users to create super-admin accounts by leveraging permissions to create a user and
<= 0.85.2
Unrestricted file upload in GLPI before 0.85.3 allows remote authenticated users to execute arbitrary code by adding a file with a
<= 0.84.7
Directory traversal vulnerability in inc/autoload.function.php in GLPI before 0.84.8 allows remote attackers to include and execut
<= 0.84.6
GLPI before 0.84.7 does not properly restrict access to cost information, which allows remote attackers to obtain sensitive inform
<= 0.85
SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to execute arbitr
<= 0.83.9
inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the _predefined_f
<= 0.83.8
Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands via the (1)
<= 0.84.1
inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is comp
<= 0.83.2
Multiple cross-site scripting (XSS) vulnerabilities in GLPI-PROJECT GLPI before 0.83.3 allow remote attackers to inject arbitrary
<= 0.83.2
Cross-site request forgery (CSRF) vulnerability in GLPI-PROJECT GLPI before 0.83.3 allows remote attackers to hijack the authentic
all versions
PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remote authenticated users to execu
<= 0.80.1
The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remot