VendorsGLPi-projectglpiany version
Vulnerabilities

GLPi-project GLPI any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

175CVEs
CVE-2023-28634
GLPI vulnerable to Privilege Escalation from Technician to Super-Admin
Published 2023-04-05 · Modified
8.8EPSS 0.008
CVE-2024-27756
GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.
Published 2024-03-15 · Analyzed
8.8EPSS 0.007
CVE-2023-41324
Account takeover through API in GLPI
Published 2023-09-26 · Modified
8.8EPSS 0.007
CVE-2023-41322
Privilege Escalation from technician to super-admin in GLPI
Published 2023-09-26 · Modified
8.8EPSS 0.007
CVE-2021-39209
Bypassable CSRF protection
Published 2021-09-15 · Modified
8.8EPSS 0.005
CVE-2024-41679
Authenticated SQL injection in ticket form
Published 2024-11-15 · Analyzed
8.8EPSS 0.005
CVE-2024-45608
GLPI has an Authenticated SQL Injection
Published 2024-11-15 · Analyzed
8.8EPSS 0.005
CVE-2024-47760
GLPI vulnerable to account takeover via API
Published 2024-12-11 · Analyzed
8.8EPSS 0.005
CVE-2024-47758
GLPI vulnerable to account takeover without privilege escalation through the API
Published 2024-12-11 · Analyzed
8.8EPSS 0.005
CVE-2026-29047
GLPI has an Authenticated SQL Injection via log exports
Published 2026-04-06 · Analyzed
8.8EPSS 0.004
CVE-2022-39234
user session persists even after permanently deleting account in GLPI
Published 2022-11-03 · Modified
8.8EPSS 0.004
CVE-2026-22044
GLPI is Vulnerable to Authenticated SQL Injection
Published 2026-02-04 · Analyzed
8.8EPSS 0.003
CVE-2020-15176
SQL injection in GLPI
Published 2020-10-07 · Modified
8.7EPSS 0.011
CVE-2024-29889
GLPI contains an SQL injection through the saved searches
Published 2024-05-07 · Analyzed
8.1EPSS 0.630
CVE-2024-37148
GLPI allows account takeover via SQL Injection in AJAX scripts
Published 2024-07-10 · Analyzed
8.1EPSS 0.202
CVE-2019-10233
Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.
Published 2019-03-27 · Modified
8.1EPSS 0.014
CVE-2023-51446
GLPI LDAP Injection during authentication
Published 2024-02-01 · Modified
8.1EPSS 0.009
CVE-2023-28632
GLPI vulnerable to account takeover by authenticated user
Published 2023-04-05 · Modified
8.1EPSS 0.007
CVE-2023-35939
GLPI vulnerable to unauthorized access to Dashboard data
Published 2023-07-05 · Modified
8.1EPSS 0.006
CVE-2024-48912
GLPI vulnerable to authenticated insecure account deletion
Published 2024-12-11 · Analyzed
8.1EPSS 0.004
CVE-2020-15177
Unauthenticated Stored XSS in GLPI
Published 2020-10-07 · Modified
8.0EPSS 0.008
CVE-2022-24867
LDAP password exposure in glpi
Published 2022-04-21 · Modified
7.8EPSS 0.013
CVE-2020-11031
Insecure encryption algorithm in GLPI
Published 2020-09-23 · Modified
7.8EPSS 0.003
CVE-2024-31456
GLPI contains an authenticated SQL injection
Published 2024-05-07 · Analyzed
7.7EPSS 0.591
CVE-2024-27096
SQL Injection in through the search engine
Published 2024-03-18 · Analyzed
7.7EPSS 0.588
CVE-2021-21326
Horizontal Privilege Escalation
Published 2021-03-08 · Modified
7.7EPSS 0.014
CVE-2020-26212
Any GLPI CalDAV calendars is read-only for every authenticated user
Published 2020-11-25 · Modified
7.7EPSS 0.012
CVE-2020-11036
XSS in GLPI
Published 2020-05-05 · Modified
7.6EPSS 0.008
CVE-2014-8360
Directory traversal vulnerability in inc/autoload.function.php in GLPI before 0.84.8 allows remote attackers to include and execute arbitrary local files via a .._ (dot dot underscore) in an item type to the getItemForItemtype, as demonstrated by the itemtype parameter in ajax/common.tabs.php.
Published 2015-04-14 · Modified
7.5EPSS 0.028
CVE-2013-2226
Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands via the (1) users_id_assign parameter to ajax/ticketassigninformation.php, (2) filename parameter to front/document.form.php, or (3) table parameter to ajax/comments.php.
Published 2014-05-14 · Modified
7.51 PoCEPSS 0.028
CVE-2021-21327
Unsafe Reflection in getItemForItemtype()
Published 2021-03-08 · Modified
7.5EPSS 0.023
CVE-2019-10477
The FusionInventory plugin before 1.4 for GLPI 9.3.x and before 1.1 for GLPI 9.4.x mishandles sendXML actions.
Published 2019-03-29 · Modified
7.5EPSS 0.018
CVE-2018-7562
A remote code execution issue was discovered in GLPI through 9.2.1. There is a race condition that allows temporary access to an uploaded executable file that will be disallowed. The application allows an authenticated user to upload a file when he/she creates a new ticket via front/fileupload.php. This feature is protected using different types of security features like the check on the file's extension. However, the application uploads and creates a file, though this file is not allowed, and then deletes the file in the uploadFiles method in inc/glpiuploaderhandler.class.php.
Published 2018-03-12 · Modified
7.5EPSS 0.017
CVE-2024-43416
GLPI vulnerable to enumeration of users' email addresses by unauthenticated user
Published 2024-11-18 · Analyzed
7.5EPSS 0.012
CVE-2023-22500
glpi Unauthorized access to inventory files
Published 2023-01-25 · Modified
7.5EPSS 0.009
CVE-2023-35940
GLPI vulnerable to unauthenticated access to Dashboard data
Published 2023-07-05 · Modified
7.5EPSS 0.007
CVE-2024-47761
GLPI vulnerable to account takeover via the password reset feature
Published 2024-12-11 · Analyzed
7.5EPSS 0.005
CVE-2022-39371
Stored Cross-Site Scripting (XSS) through asset inventory in GLPI
Published 2022-11-03 · Modified
7.5EPSS 0.005
CVE-2025-23046
GLPI vulnerable to unauthorized authentication by email using the OAuthIMAP plugin
Published 2025-02-25 · Analyzed
7.5EPSS 0.005
CVE-2024-38370
GLPI allows API document download without rights
Published 2024-11-15 · Analyzed
7.5EPSS 0.004
← Prev2 / 5Next →