VendorsGLPi-projectglpiany version
Vulnerabilities

GLPi-project GLPI any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

175CVEs
CVE-2025-64516
GLPI incorrectly authorizes access to documents
Published 2026-01-15 · Analyzed
7.5EPSS 0.003
CVE-2026-26027
GLPI has an Unauthenticated Stored XSS via inventory
Published 2026-04-06 · Analyzed
7.5EPSS 0.003
CVE-2022-24868
Cross site scripting via SVG file upload in GLPI
Published 2022-04-21 · Modified
7.3EPSS 0.006
CVE-2020-5248
Public GLPIKEY can be used to decrypt any data in GLPI
Published 2020-05-12 · Modified
7.2EPSS 0.015
CVE-2020-11033
Able to read any token through API user endpoint in GLPI
Published 2020-05-05 · Modified
7.2EPSS 0.010
CVE-2026-25932
GLPI has Stored XSS in Supplier 'Website' field
Published 2026-04-06 · Analyzed
7.2EPSS 0.003
CVE-2020-15108
SQL Injection in glpi
Published 2020-07-17 · Modified
7.1EPSS 0.012
CVE-2025-23024
GLPI: Plugins are disabled accessing one page
Published 2025-02-25 · Analyzed
6.9EPSS 0.003
CVE-2013-5696
inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection via an Etape_4 action or (2) execute arbitrary PHP code via an update_1 action.
Published 2013-09-23 · Modified
6.82 PoCEPSS 0.079
CVE-2021-21324
Insecure Direct Object Reference (IDOR) on "Solutions"
Published 2021-03-08 · Modified
6.8EPSS 0.014
CVE-2012-4002
Cross-site request forgery (CSRF) vulnerability in GLPI-PROJECT GLPI before 0.83.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Published 2012-10-09 · Modified
6.8EPSS 0.010
CVE-2022-31187
Stored Cross Site Scripting (XSS) through global search in GLPI
Published 2022-09-14 · Modified
6.8EPSS 0.007
CVE-2021-21258
XSS injection in ajax/kanban
Published 2021-03-02 · Modified
6.8EPSS 0.007
CVE-2023-22722
glpi subject to Cross-site Scripting (XSS) - Reflected
Published 2023-01-25 · Modified
6.8EPSS 0.006
CVE-2024-47759
GLPI has a stored XSS via document upload
Published 2024-11-15 · Analyzed
6.7EPSS 0.004
CVE-2024-27937
glpi Users emails enumeration
Published 2024-03-18 · Analyzed
6.5EPSS 0.271
CVE-2014-9258
SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to execute arbitrary SQL commands via the condition parameter.
Published 2014-12-19 · Modified
6.51 PoCEPSS 0.031
CVE-2024-27930
Sensitive fields access through dropdowns in GLPI
Published 2024-03-18 · Analyzed
6.5EPSS 0.011
CVE-2021-39210
Autologin cookie accessible by scripts
Published 2021-09-15 · Modified
6.5EPSS 0.010
CVE-2024-23645
GLPI reflected XSS in reports pages
Published 2024-02-01 · Modified
6.5EPSS 0.009
CVE-2022-35946
SQL injection through plugin controller in GLPI
Published 2022-09-14 · Modified
6.5EPSS 0.009
CVE-2023-41321
Sensitive fields enumeration through API in GLPI
Published 2023-09-26 · Modified
6.5EPSS 0.007
CVE-2023-23610
glpi vulnerable to Unauthorized access to data export
Published 2023-01-25 · Modified
6.5EPSS 0.007
CVE-2025-25192
GLPI allows unauthorized access to debug mode
Published 2025-02-25 · Analyzed
6.5EPSS 0.007
CVE-2023-34106
GLPI vulnerable to unauthorized access to User data
Published 2023-07-05 · Modified
6.5EPSS 0.006
CVE-2023-34107
GLPI vulnerable to unauthorized access to KnowbaseItem data
Published 2023-07-05 · Modified
6.5EPSS 0.006
CVE-2022-39376
Improper input validation on emails links in GLPI
Published 2022-11-03 · Modified
6.5EPSS 0.005
CVE-2023-34244
GLPI vulnerable to reflected XSS in search pages
Published 2023-07-05 · Modified
6.5EPSS 0.005
CVE-2024-41678
GLPI has multiple reflected XSS
Published 2024-11-15 · Analyzed
6.5EPSS 0.005
CVE-2025-21626
GLPI vulnerable to exposure of sensitive information in the `status.php` endpoint
Published 2025-02-25 · Analyzed
6.5EPSS 0.004
CVE-2024-43418
GLPI has multiple reflected XSS
Published 2024-11-15 · Analyzed
6.5EPSS 0.004
CVE-2026-23624
GLPI is vulnerable to session stealing on externally authenticated user change
Published 2026-02-04 · Analyzed
6.5EPSS 0.004
CVE-2025-21627
GLPI Cross-site Scripting vulnerability
Published 2025-02-25 · Analyzed
6.5EPSS 0.004
CVE-2024-43417
Reflected XSS in Software form
Published 2024-11-15 · Analyzed
6.5EPSS 0.004
CVE-2024-45609
GLPI has a Reflected XSS in /front/stat.graph.php
Published 2024-11-15 · Analyzed
6.5EPSS 0.003
CVE-2024-45610
GLPI has a reflected XSS in ajax/cable.php
Published 2024-11-15 · Analyzed
6.5EPSS 0.003
CVE-2025-59935
GLPI Vulnerable to Unauthenticated Stored XSS on the Inventory page
Published 2025-12-16 · Analyzed
6.5EPSS 0.003
CVE-2025-53111
GLPI exposes data to non-allowed users
Published 2025-07-30 · Analyzed
6.5EPSS 0.003
CVE-2025-53008
GLPI's MailCollector Receiver is vulnerable to credential exfiltration
Published 2025-07-30 · Analyzed
6.5EPSS 0.003
CVE-2025-64520
GLPI vulnerable to unauthorized access to restricted Knowledge Base items through the API
Published 2025-12-16 · Analyzed
6.5EPSS 0.002
← Prev3 / 5Next →