vciy

CVEs we hold for Glpi-project

Records whose assigning authority named Glpi-project as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-5385GLPI 11.0.0 - Stored XSS in knowledge baseglpi-project glpi
CVE-2026-44281GLPI vulnerable to unauthorized reading of a specific asset objectglpi-project glpi
CVE-2026-42321GLPI has stored XSS in asset locksglpi-project glpi
CVE-2026-42320GLPI vulnerable to arbitrary file accessglpi-project glpi
CVE-2026-42318GLPI Vulnerable to Arbitrary Item Deletion via Planning Endpointglpi-project glpi
CVE-2026-42317GLPI vulnerable to arbitrary files deletion by technicianglpi-project glpi
CVE-2026-40108GLPI Vulnerable to Stored XSS in ITIL Costsglpi-project glpi
CVE-2026-32312GLPI: Unauthorized export of form structureglpi-project glpi
CVE-2026-29047GLPI has an Authenticated SQL Injection via log exportsglpi-project glpi
CVE-2026-26263GLPI has an Unauthenticated SQL Injection via Search engineglpi-project glpi
CVE-2026-26027GLPI has an Unauthenticated Stored XSS via inventoryglpi-project glpi
CVE-2026-26026GLPI has a Server-Side Template Injection via Double-Compilationglpi-project glpi
CVE-2026-26001GLPI Inventory Plugin has SQL Injection on dropdown_calendar Reportglpi-project glpi-inventory-plugin
CVE-2026-25937GLPI has a MFA bypassglpi-project glpi
CVE-2026-25936GLPI Vulnerable to Authenticated SQL Injectionglpi-project glpi
CVE-2026-25932GLPI has Stored XSS in Supplier 'Website' fieldglpi-project glpi
CVE-2026-25590GLPI Inventory Plugin has Reflected XSS in task jobsglpi-project glpi-inventory-plugin
CVE-2026-23624GLPI is vulnerable to session stealing on externally authenticated user changeglpi-project glpi
CVE-2026-22248GLPI affected by Remote Code Execution via malicious uploadglpi-project glpi
CVE-2026-22247GLPI is Vulnerable to SSRF via Webhooksglpi-project glpi
CVE-2026-22044GLPI is Vulnerable to Authenticated SQL Injectionglpi-project glpi
CVE-2026-13490glpi-project glpi Document document.send.php canViewFile authorizationglpi-project glpi
CVE-2025-66417GLPI has an unauthenticated SQL injection through the inventory endpointglpi-project glpi
CVE-2025-64520GLPI vulnerable to unauthorized access to restricted Knowledge Base items through the APIglpi-project glpi
CVE-2025-64516GLPI incorrectly authorizes access to documentsglpi-project glpi
CVE-2025-59935GLPI Vulnerable to Unauthenticated Stored XSS on the Inventory pageglpi-project glpi
CVE-2025-53357GLPI permits reservation modification by unauthorized usersglpi-project glpi
CVE-2025-53113GLPI technicians can access unauthorized information through external linksglpi-project glpi
CVE-2025-53112GLPI's incomprehensive permission checks can lead to data removal from allowed usersglpi-project glpi
CVE-2025-53111GLPI exposes data to non-allowed usersglpi-project glpi
CVE-2025-53105GLPI permits unauthorized rules execution orderglpi-project glpi
CVE-2025-53008GLPI's MailCollector Receiver is vulnerable to credential exfiltrationglpi-project glpi
CVE-2025-52897GLPI is vulnerable to XSS and open redirection attacks through planning featureglpi-project glpi
CVE-2025-52567GLPI has overly permissive URL verificationglpi-project glpi
CVE-2025-32786GLPI Inventory Plugin is Vulnerable to Unauthenticated SQL Injectionglpi-project glpi-inventory-plugin
CVE-2025-27514GLPI is susceptible to Stored XSS attack through project's kanbanglpi-project glpi
CVE-2025-27147GLPI Inventory plugin has Improper Access Control Vulnerabilityglpi-project glpi-inventory-plugin
CVE-2025-26626GLPI Inventory Plugin vulnerable to reflective Cross-site Scriptingglpi-project glpi-inventory-plugin
CVE-2025-25192GLPI allows unauthorized access to debug modeglpi-project glpi
CVE-2025-24801GLPI allows authenticated remote code executionglpi-project glpi
CVE-2025-24799GLPI allows unauthenticated SQL injection through the inventory endpointglpi-project glpi
CVE-2025-23046GLPI vulnerable to unauthorized authentication by email using the OAuthIMAP pluginglpi-project glpi
CVE-2025-23024GLPI: Plugins are disabled accessing one pageglpi-project glpi
CVE-2025-21627GLPI Cross-site Scripting vulnerabilityglpi-project glpi
CVE-2025-21626GLPI vulnerable to exposure of sensitive information in the `status.php` endpointglpi-project glpi
CVE-2025-21619GLPI allows SQL injection through the rules configurationglpi-project glpi
CVE-2024-50339GLPI vulnerable to unauthenticated session hijackingglpi-project glpi
CVE-2024-48912GLPI vulnerable to authenticated insecure account deletionglpi-project glpi
CVE-2024-47761GLPI vulnerable to account takeover via the password reset featureglpi-project glpi
CVE-2024-47760GLPI vulnerable to account takeover via APIglpi-project glpi
CVE-2024-47759GLPI has a stored XSS via document uploadglpi-project glpi
CVE-2024-47758GLPI vulnerable to account takeover without privilege escalation through the APIglpi-project glpi
CVE-2024-45611GLPI has a stored XSS at src/RSSFeed.phpglpi-project glpi
CVE-2024-45610GLPI has a reflected XSS in ajax/cable.phpglpi-project glpi
CVE-2024-45609GLPI has a Reflected XSS in /front/stat.graph.phpglpi-project glpi
CVE-2024-45608GLPI has an Authenticated SQL Injectionglpi-project glpi
CVE-2024-43418GLPI has multiple reflected XSSglpi-project glpi
CVE-2024-43417Reflected XSS in Software formglpi-project glpi
CVE-2024-43416GLPI vulnerable to enumeration of users' email addresses by unauthenticated userglpi-project glpi
CVE-2024-41679Authenticated SQL injection in ticket formglpi-project glpi
CVE-2024-41678GLPI has multiple reflected XSSglpi-project glpi
CVE-2024-40638GLPI allows account takeover via SQL Injection in AJAX scriptsglpi-project glpi
CVE-2024-38370GLPI allows API document download without rightsglpi-project glpi
CVE-2024-37149GLPI allows remote code execution through the plugin loaderglpi-project glpi
CVE-2024-37148GLPI allows account takeover via SQL Injection in AJAX scriptsglpi-project glpi
CVE-2024-37147GLPI allows Authenticated File Upload to Restricted Ticketsglpi-project glpi
CVE-2024-31456GLPI contains an authenticated SQL injectionglpi-project glpi
CVE-2024-29889GLPI contains an SQL injection through the saved searchesglpi-project glpi
CVE-2024-28241GlPI-Agent MSI package installation doesn't update folder security profile when using non default installation folderglpi-project glpi-agent
CVE-2024-28240GLPI-Agent's MSI package installation permits local users to change Agent configurationglpi-project glpi-agent
CVE-2024-27937glpi Users emails enumerationglpi-project glpi
CVE-2024-27930Sensitive fields access through dropdowns in GLPIglpi-project glpi
CVE-2024-27914Reflected Cross-Site Scripting (XSS) in search engine when debug mode is enabled in GLPIglpi-project glpi
CVE-2024-27104Stored XSS in dashboards in GLPIglpi-project glpi
CVE-2024-27098Blind Server-Side Request Forgery (SSRF) using Arbitrary Object Instantiation in GLPIglpi-project glpi
CVE-2024-27096SQL Injection in through the search engineglpi-project glpi
CVE-2024-23645GLPI reflected XSS in reports pagesglpi-project glpi
CVE-2023-53943GLPI 9.5.7 Username Enumeration Vulnerability via Lost Password EndpointGlpi-Project GLPI
CVE-2023-51446GLPI LDAP Injection during authenticationglpi-project glpi
CVE-2023-46727GLPI SQL injection through inventory agent requestglpi-project glpi
CVE-2023-46726GLPI Remote code execution from LDAP server configuration form on PHP 7.4glpi-project glpi
CVE-2023-43813glpi Authenticated SQL Injectionglpi-project glpi
CVE-2023-42802GLPI vulnerable to unallowed PHP script executionglpi-project glpi
CVE-2023-42462File deletion through document upload process in GLPIglpi-project glpi
CVE-2023-42461SQL injection in ITIL actors in GLPIglpi-project glpi
CVE-2023-41888Phishing through a login page malicious URL in GLPIglpi-project glpi
CVE-2023-41326Account takeover via Kanban feature in GLPIglpi-project glpi
CVE-2023-41324Account takeover through API in GLPIglpi-project glpi
CVE-2023-41323Users login enumeration by unauthenticated user in GLPIglpi-project glpi
CVE-2023-41322Privilege Escalation from technician to super-admin in GLPIglpi-project glpi
CVE-2023-41321Sensitive fields enumeration through API in GLPIglpi-project glpi
CVE-2023-41320Account takeover via SQL Injection in UI layout preferences in GLPIglpi-project glpi
CVE-2023-37278GLPI vulnerable to SQL injection via dashboard administrationglpi-project glpi
CVE-2023-36808GLPI vulnerable to SQL injection through Computer Virtual Machine informationglpi-project glpi
CVE-2023-35940GLPI vulnerable to unauthenticated access to Dashboard dataglpi-project glpi
CVE-2023-35939GLPI vulnerable to unauthorized access to Dashboard dataglpi-project glpi
CVE-2023-35924GLPI vulnerable to SQL injection via inventory agent requestglpi-project glpi
CVE-2023-34254Remote inventory task command injection when using ssh command modeglpi-project glpi-agent
CVE-2023-34244GLPI vulnerable to reflected XSS in search pagesglpi-project glpi
CVE-2023-34107GLPI vulnerable to unauthorized access to KnowbaseItem dataglpi-project glpi
CVE-2023-34106GLPI vulnerable to unauthorized access to User dataglpi-project glpi
CVE-2023-28852GLPI vulnerable to stored Cross-site Scripting through dashboard administrationglpi-project glpi
CVE-2023-28849GLPI vulnerable to SQL injection and Stored XSS via inventory agent requestglpi-project glpi
CVE-2023-28838GLPI vulnerable to SQL injection through dynamic reportsglpi-project glpi
CVE-2023-28636GLPI vulnerable to stored Cross-site Scripting in external linksglpi-project glpi
CVE-2023-28634GLPI vulnerable to Privilege Escalation from Technician to Super-Adminglpi-project glpi
CVE-2023-28633GLPI vulnerable to Blind Server-Side Request Forgery (SSRF) in RSS feedsglpi-project glpi
CVE-2023-28632GLPI vulnerable to account takeover by authenticated userglpi-project glpi
CVE-2023-23610glpi vulnerable to Unauthorized access to data exportglpi-project glpi
CVE-2023-22725glpi vulnerable to XSS on external linksglpi-project glpi
CVE-2023-22724glpi contains XSS in RSS Description Linkglpi-project glpi
CVE-2023-22722glpi subject to Cross-site Scripting (XSS) - Reflectedglpi-project glpi
CVE-2023-22500glpi Unauthorized access to inventory filesglpi-project glpi
CVE-2022-41941glpi contains XSS Stored inside Standard Interface Help Link href attributeglpi-project glpi
CVE-2022-39376Improper input validation on emails links in GLPIglpi-project glpi
CVE-2022-39375Cross-Site Scripting (XSS) through public RSS feed in GLPIglpi-project glpi
CVE-2022-39373Stored Cross-Site Scripting (XSS) in entity name in GLPIglpi-project glpi
CVE-2022-39372Stored Cross-Site Scripting (XSS) in user information in GLPIglpi-project glpi
CVE-2022-39371Stored Cross-Site Scripting (XSS) through asset inventory in GLPIglpi-project glpi
CVE-2022-39370Improper access to debug panel in GLPIglpi-project glpi
CVE-2022-39323SQL Injection on REST API in GLPIglpi-project glpi
CVE-2022-39277Cross-Site Scripting (XSS) in external links in GLPIglpi-project glpi
CVE-2022-39276Blind Server-Side Request Forgery (SSRF) in RSS feeds and planningglpi-project glpi
CVE-2022-39262Stored Cross-Site Scripting (XSS) on login page in GLPIglpi-project glpi
CVE-2022-39234user session persists even after permanently deleting account in GLPIglpi-project glpi
CVE-2022-36112Blind Server-Side Request Forgery (SSRF) in GLPIglpi-project glpi
CVE-2022-35947SQL injection in GLPIglpi-project glpi
CVE-2022-35946SQL injection through plugin controller in GLPIglpi-project glpi
CVE-2022-35945Cross site scripting (XSS) via registration API in GLPIglpi-project glpi
CVE-2022-31187Stored Cross Site Scripting (XSS) through global search in GLPIglpi-project glpi
CVE-2022-31143Leak of sensitive information through login page error in GLPIglpi-project glpi
CVE-2022-31082SQL Injection via package deployment tasks in glpi-inventory-pluginglpi-project glpi-inventory-plugin
CVE-2022-31068Sensitive Data Exposure on Refused Inventory Files in GLPIglpi-project glpi
CVE-2022-31062Unauthenticated Local File Inclusionglpi-project glpi-inventory-plugin
CVE-2022-31061SQL injection on login page in GLPIglpi-project glpi
CVE-2022-31056SQL injection with _actor parameter in GLPIglpi-project glpi
CVE-2022-29250SQL injection in GLPIglpi-project glpi
CVE-2022-24876Stored cross site scrpting in GLPI's Kanbanglpi-project glpi
CVE-2022-24869Cross Site Scripting in GLPIglpi-project glpi
CVE-2022-24868Cross site scripting via SVG file upload in GLPIglpi-project glpi
CVE-2022-24867LDAP password exposure in glpiglpi-project glpi
CVE-2021-39213IP restriction on GLPI API Bypass with custom header injectionglpi-project glpi
CVE-2021-39211Disclosure of GLPI and server information in telemetry endpointglpi-project glpi
CVE-2021-39210Autologin cookie accessible by scriptsglpi-project glpi
CVE-2021-39209Bypassable CSRF protectionglpi-project glpi
CVE-2021-21327Unsafe Reflection in getItemForItemtype()glpi-project glpi
CVE-2021-21326Horizontal Privilege Escalationglpi-project glpi
CVE-2021-21325Stored XSS in budget typeglpi-project glpi
CVE-2021-21324Insecure Direct Object Reference (IDOR) on "Solutions"glpi-project glpi
CVE-2021-21314XSS injection on ticket updateglpi-project glpi
CVE-2021-21313XSS on tabsglpi-project glpi
CVE-2021-21312Stored XSS on documentsglpi-project glpi
CVE-2021-21258XSS injection in ajax/kanbanglpi-project glpi
CVE-2021-21255entities switch IDORglpi-project glpi
CVE-2020-5248Public GLPIKEY can be used to decrypt any data in GLPIglpi-project glpi
CVE-2020-26212Any GLPI CalDAV calendars is read-only for every authenticated userglpi-project glpi
CVE-2020-15226SQL Injection in GLPI Search APIglpi-project glpi
CVE-2020-15217User data exposure in GLPIglpi-project glpi
CVE-2020-15177Unauthenticated Stored XSS in GLPIglpi-project glpi
CVE-2020-15176SQL injection in GLPIglpi-project glpi
CVE-2020-15175Unauthenticated File Deletion in GLPIglpi-project glpi
CVE-2020-15108SQL Injection in glpiglpi-project glpi
CVE-2020-11060Remote Code Execution in GLPIglpi-project GLPI
CVE-2020-11036XSS in GLPIglpi-project GLPI
CVE-2020-11035weak CSRF tokens in GLPIglpi-project GLPI
CVE-2020-11034bypass of manageRedirect in GLPIglpi-project GLPI
CVE-2020-11033Able to read any token through API user endpoint in GLPIglpi-project GLPI
CVE-2020-11032SQL injection on addme_observer and addme_assign in GLPIglpi-project GLPI
CVE-2020-11031Insecure encryption algorithm in GLPIglpi-project GLPI

169 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.