VendorsGLPi-projectglpiany version
Vulnerabilities

GLPi-project GLPI any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

175CVEs
CVE-2025-52897
GLPI is vulnerable to XSS and open redirection attacks through planning feature
Published 2025-07-30 · Analyzed
6.5EPSS 0.002
CVE-2013-2225
inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the _predefined_fields parameter to front/ticket.form.php.
Published 2014-05-27 · Modified
6.41 PoCEPSS 0.076
CVE-2022-35945
Cross site scripting (XSS) via registration API in GLPI
Published 2022-09-14 · Modified
6.3EPSS 0.007
CVE-2021-21325
Stored XSS in budget type
Published 2021-03-08 · Modified
6.2EPSS 0.006
CVE-2023-22725
glpi vulnerable to XSS on external links
Published 2023-01-25 · Modified
6.2EPSS 0.006
CVE-2022-41941
glpi contains XSS Stored inside Standard Interface Help Link href attribute
Published 2023-01-25 · Modified
6.2EPSS 0.006
CVE-2023-22724
glpi contains XSS in RSS Description Link
Published 2023-01-25 · Modified
6.2EPSS 0.006
CVE-2020-11034
bypass of manageRedirect in GLPI
Published 2020-05-05 · Modified
6.1EPSS 0.076
CVE-2019-13239
inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.
Published 2019-07-04 · Modified
6.1EPSS 0.013
CVE-2018-7563
An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by the attacker. The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.
Published 2018-03-12 · Modified
6.1EPSS 0.011
CVE-2022-21719
Reflected XSS using reload button in GLPI
Published 2022-01-28 · Modified
6.1EPSS 0.010
CVE-2021-21313
XSS on tabs
Published 2021-03-03 · Modified
6.1EPSS 0.009
CVE-2024-27914
Reflected Cross-Site Scripting (XSS) in search engine when debug mode is enabled in GLPI
Published 2024-03-18 · Analyzed
6.1EPSS 0.008
CVE-2023-28639
GLPI vulnerable to reflected Cross-site Scripting in search pages
Published 2023-04-05 · Modified
6.1EPSS 0.006
CVE-2024-11955
GLPI index.php redirect
Published 2025-02-25 · Analyzed
6.1EPSS 0.005
CVE-2020-11062
Reflexive XSS in GLPI
Published 2020-05-12 · Modified
6.0EPSS 0.005
CVE-2019-13240
An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any information except the associated email address.
Published 2019-07-10 · Modified
5.9EPSS 0.017
CVE-2022-36112
Blind Server-Side Request Forgery (SSRF) in GLPI
Published 2022-09-14 · Modified
5.8EPSS 0.006
CVE-2024-45611
GLPI has a stored XSS at src/RSSFeed.php
Published 2024-11-15 · Analyzed
5.7EPSS 0.003
CVE-2017-11183
front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.
Published 2017-07-28 · Modified
5.5EPSS 0.013
CVE-2022-24869
Cross Site Scripting in GLPI
Published 2022-04-21 · Modified
5.4EPSS 0.008
CVE-2021-21312
Stored XSS on documents
Published 2021-03-03 · Modified
5.4EPSS 0.006
CVE-2021-21314
XSS injection on ticket update
Published 2021-03-03 · Modified
5.4EPSS 0.006
CVE-2022-39375
Cross-Site Scripting (XSS) through public RSS feed in GLPI
Published 2022-11-03 · Modified
5.4EPSS 0.005
CVE-2023-28633
GLPI vulnerable to Blind Server-Side Request Forgery (SSRF) in RSS feeds
Published 2023-04-05 · Modified
5.4EPSS 0.005
CVE-2022-39372
Stored Cross-Site Scripting (XSS) in user information in GLPI
Published 2022-11-03 · Modified
5.4EPSS 0.004
CVE-2023-41888
Phishing through a login page malicious URL in GLPI
Published 2023-09-26 · Modified
5.4EPSS 0.004
CVE-2025-27514
GLPI is susceptible to Stored XSS attack through project's kanban
Published 2025-07-29 · Analyzed
5.4EPSS 0.002
CVE-2025-53357
GLPI permits reservation modification by unauthorized users
Published 2025-07-30 · Analyzed
5.4EPSS 0.002
CVE-2023-41323
Users login enumeration by unauthenticated user in GLPI
Published 2023-09-26 · Modified
5.3EPSS 0.339
CVE-2021-39211
Disclosure of GLPI and server information in telemetry endpoint
Published 2021-09-15 · Modified
5.3EPSS 0.047
CVE-2020-15217
User data exposure in GLPI
Published 2020-10-07 · Modified
5.3EPSS 0.010
CVE-2022-31068
Sensitive Data Exposure on Refused Inventory Files in GLPI
Published 2022-06-28 · Modified
5.3EPSS 0.009
CVE-2022-31143
Leak of sensitive information through login page error in GLPI
Published 2022-09-14 · Modified
5.3EPSS 0.008
CVE-2022-39276
Blind Server-Side Request Forgery (SSRF) in RSS feeds and planning
Published 2022-11-03 · Modified
5.3EPSS 0.006
CVE-2022-39262
Stored Cross-Site Scripting (XSS) on login page in GLPI
Published 2022-11-03 · Modified
5.2EPSS 0.007
CVE-2026-32312
GLPI: Unauthorized export of form structure
Published 2026-05-18 · Analyzed
5.1EPSS 0.003
CVE-2011-2720
The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.
Published 2011-08-05 · Modified
5.0EPSS 0.029
CVE-2014-5032
GLPI before 0.84.7 does not properly restrict access to cost information, which allows remote attackers to obtain sensitive information via the cost criteria in the search bar.
Published 2015-04-14 · Modified
5.0EPSS 0.021
CVE-2020-15226
SQL Injection in GLPI Search API
Published 2020-10-07 · Modified
5.0EPSS 0.010
← Prev4 / 5Next →