Vulnerabilities
191 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-32312 | GLPI is a free asset and IT management software package. GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue has been fixed in version 11.0.7. NVD description · AI analysis pending | 5.1 | <1% |
| — | ||
| CVE-2026-26263 | GLPI is a free asset and IT management software package. GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6. NVD description · AI analysis pending | 9.8 group max | 8% |
| — | ||
| CVE-2026-26001 | The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, non sanitized user input can lend to an SQL injection from reports, with adequate rights. This vulnerability is fixed in 1.6.6. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2026-25590 | The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, there is a reflected XSS vulnerability in task jobs. This vulnerability is fixed in 1.6.6. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2026-22821 | mreporting is the more reporting GLPI plugin. mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vulnerability is fixed in 1.9.4. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2026-22247 | GLPI is a free asset and IT management software package. GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issue has been patched in version 11.0.5. NVD description · AI analysis pending | 9.1 group max | <1% |
| — | ||
| CVE-2025-66417 +1 in the same advisory: …64516 | GLPI is a free asset and IT management software package. GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2023-53943 | GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email addresses by submitting requests to the password reset endpoint and analyzing response differences to identify valid user accounts. NVD description · AI analysis pending | 6.9 | <1% | PoC |
| — | |
| CVE-2025-59935 +1 in the same advisory: …64520 | GLPI is a free asset and IT management software package. GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inventory endpoint. Users should upgrade to 10.0.21 to receive a patch. NVD description · AI analysis pending | 6.5 group max | <1% |
| — | ||
| CVE-2025-53111 | GLPI is a Free Asset and IT Management Software package. GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized access to some resources. This is fixed in version 10.0.19. NVD description · AI analysis pending | 6.5 group max | <1% |
| — | ||
| CVE-2025-27514 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a technician can use a malicious payload to trigger a stored XSS on the project's kanban. This is fixed in version 10.0.19. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2025-24799 | Unauthenticated SQL Injection in GLPI Inventory Endpoint GLPI, a widely used open-source IT asset and service management platform, contains an unauthenticated SQL injection flaw (CWE-89) in its inventory endpoint. An attacker can trigger it by sending specially crafted, unauthenticated requests to that endpoint, causing attacker-controlled input to be executed within SQL queries. Successful exploitation could allow reading or modifying the GLPI database, exposing sensitive IT asset and configuration data and potentially further access, consistent with the critical 9.8 CVSS score (high confidentiality, integrity and availability impact). Any GLPI deployment running a version earlier than 10.0.18 is affected, particularly instances whose inventory endpoint is reachable by untrusted clients. A public proof-of-concept exists and the flaw is not yet in CISA's KEV, but EPSS assigns an 86.3% probability of exploitation within 30 days (100th percentile), indicating elevated exploitation risk. Do: Upgrade to GLPI 10.0.18 or later immediately, prioritizing instances whose inventory endpoint is exposed to untrusted networks or the internet. If patching must be delayed, restrict access to the inventory endpoint (e.g., limit to known agent source IPs or internal networks) and review logs for anomalous or unauthenticated inventory requests. Note that exploitation requires no authentication or user interaction, so do not rely on access controls alone. | 9.8 group max | 86% | PoC |
| large≈tens of thousands of GLPI installations, with thousands of instances plausibly internet-exposed | |
| CVE-2025-23024 | GLPI is a free asset and IT management software package. GLPI is a free asset and IT management software package. Starting in version 0.72 and prior to version 10.0.18, an anonymous user can disable all the active plugins. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` file. NVD description · AI analysis pending | 6.9 group max | <1% |
| — | ||
| CVE-2024-50339 | GLPI is a free asset and IT management software package. GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version 10.0.17 contains a patch for this issue. NVD description · AI analysis pending | 9.3 | 20% |
| — | ||
| CVE-2024-47758 | GLPI is a free asset and IT management software package. GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the API to take control of any user that have the same or a lower level of privileges. Version 10.0.17 contains a patch for this issue. NVD description · AI analysis pending | 7.6 group max | <1% |
| — | ||
| CVE-2024-43416 | GLPI is a free asset and IT management software package. GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an unauthenticated user can use an application endpoint to check if an email address corresponds to a valid GLPI user. Version 10.0.17 fixes the issue. NVD description · AI analysis pending | 5.3 | 1% |
| — | ||
| CVE-2024-45608 | GLPI is a free asset and IT management software package. GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing its preferences. Upgrade to 10.0.17. NVD description · AI analysis pending | 8.8 group max | <1% |
| — |