glpi-project glpi

14 known vulnerabilities in glpi-project glpi, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-55217 CVSS 5.3 medium GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can…
  • CVE-2026-55214 CVSS 8.5 high GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in…
  • CVE-2026-53629 CVSS 7.1 high GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can…
  • CVE-2026-53628 CVSS 5.9 medium GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and…
  • CVE-2026-53627 CVSS 6.0 medium GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API…
  • CVE-2026-53626 CVSS 7.1 high GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant…
  • CVE-2026-53625 CVSS 7.5 high GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype…
  • CVE-2026-53610 CVSS 7.5 high GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that…
  • CVE-2026-49470 CVSS 7.7 high GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint…
  • CVE-2026-49469 CVSS 4.6 medium GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can…
  • CVE-2026-48482 CVSS 9.4 critical GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted…
  • CVE-2026-47679 CVSS 8.5 high GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit…
  • CVE-2026-45801 CVSS 5.3 medium GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required…
  • CVE-2025-24799 CVSS 9.8 critical GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory…