VendorsGLPi-projectglpiany version
Vulnerabilities

GLPi-project GLPI any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

175CVEs
CVE-2022-35947
SQL injection in GLPI
Published 2022-09-14 · Modified
10.0EPSS 0.012
CVE-2023-42802
GLPI vulnerable to unallowed PHP script execution
Published 2023-11-02 · Modified
10.0EPSS 0.008
CVE-2023-28849
GLPI vulnerable to SQL injection and Stored XSS via inventory agent request
Published 2023-04-05 · Modified
10.0EPSS 0.005
CVE-2022-35914
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
Published 2022-09-19 · Analyzed
9.8KEV1 PoCEPSS 0.999
CVE-2025-24799
GLPI allows unauthenticated SQL injection through the inventory endpoint
Published 2025-03-18 · Analyzed
9.8EPSS 0.867
CVE-2023-46727
GLPI SQL injection through inventory agent request
Published 2023-12-13 · Modified
9.8EPSS 0.677
CVE-2022-31061
SQL injection on login page in GLPI
Published 2022-06-28 · Modified
9.8EPSS 0.514
CVE-2023-35924
GLPI vulnerable to SQL injection via inventory agent request
Published 2023-07-05 · Modified
9.8EPSS 0.507
CVE-2023-36808
GLPI vulnerable to SQL injection through Computer Virtual Machine information
Published 2023-07-05 · Modified
9.8EPSS 0.478
CVE-2022-39323
SQL Injection on REST API in GLPI
Published 2022-11-03 · Modified
9.8EPSS 0.345
CVE-2023-41320
Account takeover via SQL Injection in UI layout preferences in GLPI
Published 2023-09-26 · Modified
9.8EPSS 0.319
CVE-2022-31056
SQL injection with _actor parameter in GLPI
Published 2022-06-28 · Modified
9.81 PoCEPSS 0.090
CVE-2017-11184
SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.
Published 2017-07-28 · Modified
9.8EPSS 0.016
CVE-2017-11474
GLPI before 9.1.5.1 has SQL Injection in the $crit variable in inc/computer_softwareversion.class.php, exploitable via ajax/common.tabs.php.
Published 2017-07-20 · Modified
9.8EPSS 0.014
CVE-2023-46726
GLPI Remote code execution from LDAP server configuration form on PHP 7.4
Published 2023-12-13 · Modified
9.8EPSS 0.013
CVE-2017-11329
GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers.
Published 2017-07-14 · Modified
9.8EPSS 0.012
CVE-2023-42461
SQL injection in ITIL actors in GLPI
Published 2023-09-26 · Modified
9.8EPSS 0.009
CVE-2025-66417
GLPI has an unauthenticated SQL injection through the inventory endpoint
Published 2026-01-15 · Analyzed
9.8EPSS 0.005
CVE-2025-21619
GLPI allows SQL injection through the rules configuration
Published 2025-03-18 · Analyzed
9.8EPSS 0.004
CVE-2026-26263
GLPI has an Unauthenticated SQL Injection via Search engine
Published 2026-04-06 · Analyzed
9.8EPSS 0.004
CVE-2024-27098
Blind Server-Side Request Forgery (SSRF) using Arbitrary Object Instantiation in GLPI
Published 2024-03-18 · Analyzed
9.6EPSS 0.357
CVE-2023-28838
GLPI vulnerable to SQL injection through dynamic reports
Published 2023-04-05 · Modified
9.6EPSS 0.008
CVE-2024-50339
GLPI vulnerable to unauthenticated session hijacking
Published 2024-12-11 · Analyzed
9.3EPSS 0.187
CVE-2020-11035
weak CSRF tokens in GLPI
Published 2020-05-05 · Modified
9.3EPSS 0.008
CVE-2020-15175
Unauthenticated File Deletion in GLPI
Published 2020-10-07 · Modified
9.1EPSS 0.716
CVE-2023-42462
File deletion through document upload process in GLPI
Published 2023-09-26 · Modified
9.1EPSS 0.010
CVE-2023-37278
GLPI vulnerable to SQL injection via dashboard administration
Published 2023-07-13 · Modified
9.1EPSS 0.007
CVE-2026-26026
GLPI has a Server-Side Template Injection via Double-Compilation
Published 2026-04-06 · Analyzed
9.1EPSS 0.005
CVE-2026-22247
GLPI is Vulnerable to SSRF via Webhooks
Published 2026-02-04 · Analyzed
9.1EPSS 0.003
CVE-2020-11060
Remote Code Execution in GLPI
Published 2020-05-12 · Modified
9.02 PoCEPSS 0.109
CVE-2015-7684
Unrestricted file upload in GLPI before 0.85.3 allows remote authenticated users to execute arbitrary code by adding a file with an executable extension as an attachment to a new ticket, then accessing it via a direct request to the file in files/_tmp/.
Published 2015-10-05 · Modified
9.0EPSS 0.041
CVE-2024-40638
GLPI allows account takeover via SQL Injection in AJAX scripts
Published 2024-11-15 · Analyzed
8.8EPSS 0.374
CVE-2023-41326
Account takeover via Kanban feature in GLPI
Published 2023-09-26 · Modified
8.8EPSS 0.312
CVE-2023-43813
glpi Authenticated SQL Injection
Published 2023-12-13 · Modified
8.8EPSS 0.309
CVE-2024-37149
GLPI allows remote code execution through the plugin loader
Published 2024-07-10 · Analyzed
8.8EPSS 0.211
CVE-2025-24801
GLPI allows authenticated remote code execution
Published 2025-03-18 · Analyzed
8.8EPSS 0.210
CVE-2019-14666
GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability can be exploited to take control of admin account. This vulnerability could be also abused to obtain other sensitive fields like API keys or password hashes.
Published 2019-09-25 · Modified
8.8EPSS 0.022
CVE-2018-13049
The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by triggering a crafted LIMIT clause to front/computer.php.
Published 2018-07-02 · Modified
8.8EPSS 0.012
CVE-2017-11475
GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.
Published 2017-07-20 · Modified
8.8EPSS 0.012
CVE-2021-39213
IP restriction on GLPI API Bypass with custom header injection
Published 2021-09-15 · Modified
8.8EPSS 0.011
1 / 5Next →