VendorsGLPi-projectglpiall versions
Vulnerabilities

GLPi-project GLPI

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

189CVEs
CVE-2025-27514
GLPI is susceptible to Stored XSS attack through project's kanban
Published 2025-07-29 · Analyzed
5.4EPSS 0.002
CVE-2025-53357
GLPI permits reservation modification by unauthorized users
Published 2025-07-30 · Analyzed
5.4EPSS 0.002
CVE-2023-41323
Users login enumeration by unauthenticated user in GLPI
Published 2023-09-26 · Modified
5.3EPSS 0.339
CVE-2021-39211
Disclosure of GLPI and server information in telemetry endpoint
Published 2021-09-15 · Modified
5.3EPSS 0.047
CVE-2020-15217
User data exposure in GLPI
Published 2020-10-07 · Modified
5.3EPSS 0.010
CVE-2022-31068
Sensitive Data Exposure on Refused Inventory Files in GLPI
Published 2022-06-28 · Modified
5.3EPSS 0.009
CVE-2022-31143
Leak of sensitive information through login page error in GLPI
Published 2022-09-14 · Modified
5.3EPSS 0.008
CVE-2022-39276
Blind Server-Side Request Forgery (SSRF) in RSS feeds and planning
Published 2022-11-03 · Modified
5.3EPSS 0.006
CVE-2022-39262
Stored Cross-Site Scripting (XSS) on login page in GLPI
Published 2022-11-03 · Modified
5.2EPSS 0.007
CVE-2026-32312
GLPI: Unauthorized export of form structure
Published 2026-05-18 · Analyzed
5.1EPSS 0.003
CVE-2011-2720
The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.
Published 2011-08-05 · Modified
5.0EPSS 0.029
CVE-2014-5032
GLPI before 0.84.7 does not properly restrict access to cost information, which allows remote attackers to obtain sensitive information via the cost criteria in the search bar.
Published 2015-04-14 · Modified
5.0EPSS 0.021
CVE-2020-15226
SQL Injection in GLPI Search API
Published 2020-10-07 · Modified
5.0EPSS 0.010
CVE-2025-52567
GLPI has overly permissive URL verification
Published 2025-07-30 · Analyzed
5.0EPSS 0.002
CVE-2022-21720
SQL injection using custom CSS administration form in GLPI
Published 2022-01-28 · Modified
4.9EPSS 0.011
CVE-2022-39373
Stored Cross-Site Scripting (XSS) in entity name in GLPI
Published 2022-11-03 · Modified
4.9EPSS 0.005
CVE-2024-27104
Stored XSS in dashboards in GLPI
Published 2024-03-18 · Analyzed
4.8EPSS 0.007
CVE-2023-28636
GLPI vulnerable to stored Cross-site Scripting in external links
Published 2023-04-05 · Modified
4.8EPSS 0.006
CVE-2022-39277
Cross-Site Scripting (XSS) in external links in GLPI
Published 2022-11-03 · Modified
4.8EPSS 0.006
CVE-2023-28852
GLPI vulnerable to stored Cross-site Scripting through dashboard administration
Published 2023-04-05 · Modified
4.8EPSS 0.005
CVE-2012-4003
Multiple cross-site scripting (XSS) vulnerabilities in GLPI-PROJECT GLPI before 0.83.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
Published 2012-10-09 · Modified
4.3EPSS 0.018
CVE-2020-27663
In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.).
Published 2020-11-26 · Modified
4.3EPSS 0.009
CVE-2020-27662
In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.).
Published 2020-11-26 · Modified
4.3EPSS 0.007
CVE-2024-37147
GLPI allows Authenticated File Upload to Restricted Tickets
Published 2024-07-10 · Analyzed
4.3EPSS 0.007
CVE-2022-39370
Improper access to debug panel in GLPI
Published 2022-11-03 · Modified
4.3EPSS 0.005
CVE-2025-53112
GLPI's incomprehensive permission checks can lead to data removal from allowed users
Published 2025-07-30 · Analyzed
4.3EPSS 0.002
CVE-2015-7685
GLPI before 0.85.3 allows remote authenticated users to create super-admin accounts by leveraging permissions to create a user and the _profiles_id parameter to front/user.form.php.
Published 2015-10-05 · Modified
4.0EPSS 0.017
CVE-2019-1010310
GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The component is: Tools > Reminder > Description .. Set the description to any iframe/form tags and apply. The attack vector is: The attacker puts a login form, the user fills it and clicks on submit .. the request is sent to the attacker domain saving the data. The fixed version is: 9.4.1.
Published 2019-07-12 · Modified
3.5EPSS 0.007
CVE-2025-53113
GLPI technicians can access unauthorized information through external links
Published 2025-07-30 · Analyzed
2.7EPSS 0.002
← Prev5 / 5