VendorsGLPi-projectglpiany version
Vulnerabilities

GLPi-project GLPI any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

175CVEs
CVE-2025-52567
GLPI has overly permissive URL verification
Published 2025-07-30 · Analyzed
5.0EPSS 0.002
CVE-2022-21720
SQL injection using custom CSS administration form in GLPI
Published 2022-01-28 · Modified
4.9EPSS 0.011
CVE-2022-39373
Stored Cross-Site Scripting (XSS) in entity name in GLPI
Published 2022-11-03 · Modified
4.9EPSS 0.005
CVE-2024-27104
Stored XSS in dashboards in GLPI
Published 2024-03-18 · Analyzed
4.8EPSS 0.007
CVE-2023-28636
GLPI vulnerable to stored Cross-site Scripting in external links
Published 2023-04-05 · Modified
4.8EPSS 0.006
CVE-2022-39277
Cross-Site Scripting (XSS) in external links in GLPI
Published 2022-11-03 · Modified
4.8EPSS 0.006
CVE-2023-28852
GLPI vulnerable to stored Cross-site Scripting through dashboard administration
Published 2023-04-05 · Modified
4.8EPSS 0.005
CVE-2012-4003
Multiple cross-site scripting (XSS) vulnerabilities in GLPI-PROJECT GLPI before 0.83.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
Published 2012-10-09 · Modified
4.3EPSS 0.018
CVE-2020-27663
In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.).
Published 2020-11-26 · Modified
4.3EPSS 0.009
CVE-2020-27662
In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.).
Published 2020-11-26 · Modified
4.3EPSS 0.007
CVE-2024-37147
GLPI allows Authenticated File Upload to Restricted Tickets
Published 2024-07-10 · Analyzed
4.3EPSS 0.007
CVE-2022-39370
Improper access to debug panel in GLPI
Published 2022-11-03 · Modified
4.3EPSS 0.005
CVE-2025-53112
GLPI's incomprehensive permission checks can lead to data removal from allowed users
Published 2025-07-30 · Analyzed
4.3EPSS 0.002
CVE-2015-7685
GLPI before 0.85.3 allows remote authenticated users to create super-admin accounts by leveraging permissions to create a user and the _profiles_id parameter to front/user.form.php.
Published 2015-10-05 · Modified
4.0EPSS 0.017
CVE-2025-53113
GLPI technicians can access unauthorized information through external links
Published 2025-07-30 · Analyzed
2.7EPSS 0.002
← Prev5 / 5