Home / CVEs we hold for Glpi-project CVEs we hold for Glpi-project Records whose assigning authority named Glpi-project as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-5385 GLPI 11.0.0 - Stored XSS in knowledge base glpi-project glpi CVE-2026-44281 GLPI vulnerable to unauthorized reading of a specific asset object glpi-project glpi CVE-2026-42320 GLPI vulnerable to arbitrary file access glpi-project glpi CVE-2026-42318 GLPI Vulnerable to Arbitrary Item Deletion via Planning Endpoint glpi-project glpi CVE-2026-42317 GLPI vulnerable to arbitrary files deletion by technician glpi-project glpi CVE-2026-40108 GLPI Vulnerable to Stored XSS in ITIL Costs glpi-project glpi CVE-2026-32312 GLPI: Unauthorized export of form structure glpi-project glpi CVE-2026-29047 GLPI has an Authenticated SQL Injection via log exports glpi-project glpi CVE-2026-26263 GLPI has an Unauthenticated SQL Injection via Search engine glpi-project glpi CVE-2026-26027 GLPI has an Unauthenticated Stored XSS via inventory glpi-project glpi CVE-2026-26026 GLPI has a Server-Side Template Injection via Double-Compilation glpi-project glpi CVE-2026-26001 GLPI Inventory Plugin has SQL Injection on dropdown_calendar Report glpi-project glpi-inventory-plugin CVE-2026-25936 GLPI Vulnerable to Authenticated SQL Injection glpi-project glpi CVE-2026-25932 GLPI has Stored XSS in Supplier 'Website' field glpi-project glpi CVE-2026-25590 GLPI Inventory Plugin has Reflected XSS in task jobs glpi-project glpi-inventory-plugin CVE-2026-23624 GLPI is vulnerable to session stealing on externally authenticated user change glpi-project glpi CVE-2026-22248 GLPI affected by Remote Code Execution via malicious upload glpi-project glpi CVE-2026-22247 GLPI is Vulnerable to SSRF via Webhooks glpi-project glpi CVE-2026-22044 GLPI is Vulnerable to Authenticated SQL Injection glpi-project glpi CVE-2026-13490 glpi-project glpi Document document.send.php canViewFile authorization glpi-project glpi CVE-2025-66417 GLPI has an unauthenticated SQL injection through the inventory endpoint glpi-project glpi CVE-2025-64520 GLPI vulnerable to unauthorized access to restricted Knowledge Base items through the API glpi-project glpi CVE-2025-64516 GLPI incorrectly authorizes access to documents glpi-project glpi CVE-2025-59935 GLPI Vulnerable to Unauthenticated Stored XSS on the Inventory page glpi-project glpi CVE-2025-53357 GLPI permits reservation modification by unauthorized users glpi-project glpi CVE-2025-53113 GLPI technicians can access unauthorized information through external links glpi-project glpi CVE-2025-53112 GLPI's incomprehensive permission checks can lead to data removal from allowed users glpi-project glpi CVE-2025-53105 GLPI permits unauthorized rules execution order glpi-project glpi CVE-2025-53008 GLPI's MailCollector Receiver is vulnerable to credential exfiltration glpi-project glpi CVE-2025-52897 GLPI is vulnerable to XSS and open redirection attacks through planning feature glpi-project glpi CVE-2025-52567 GLPI has overly permissive URL verification glpi-project glpi CVE-2025-32786 GLPI Inventory Plugin is Vulnerable to Unauthenticated SQL Injection glpi-project glpi-inventory-plugin CVE-2025-27514 GLPI is susceptible to Stored XSS attack through project's kanban glpi-project glpi CVE-2025-27147 GLPI Inventory plugin has Improper Access Control Vulnerability glpi-project glpi-inventory-plugin CVE-2025-26626 GLPI Inventory Plugin vulnerable to reflective Cross-site Scripting glpi-project glpi-inventory-plugin CVE-2025-25192 GLPI allows unauthorized access to debug mode glpi-project glpi CVE-2025-24801 GLPI allows authenticated remote code execution glpi-project glpi CVE-2025-24799 GLPI allows unauthenticated SQL injection through the inventory endpoint glpi-project glpi CVE-2025-23046 GLPI vulnerable to unauthorized authentication by email using the OAuthIMAP plugin glpi-project glpi CVE-2025-23024 GLPI: Plugins are disabled accessing one page glpi-project glpi CVE-2025-21627 GLPI Cross-site Scripting vulnerability glpi-project glpi CVE-2025-21626 GLPI vulnerable to exposure of sensitive information in the `status.php` endpoint glpi-project glpi CVE-2025-21619 GLPI allows SQL injection through the rules configuration glpi-project glpi CVE-2024-50339 GLPI vulnerable to unauthenticated session hijacking glpi-project glpi CVE-2024-48912 GLPI vulnerable to authenticated insecure account deletion glpi-project glpi CVE-2024-47761 GLPI vulnerable to account takeover via the password reset feature glpi-project glpi CVE-2024-47760 GLPI vulnerable to account takeover via API glpi-project glpi CVE-2024-47759 GLPI has a stored XSS via document upload glpi-project glpi CVE-2024-47758 GLPI vulnerable to account takeover without privilege escalation through the API glpi-project glpi CVE-2024-45611 GLPI has a stored XSS at src/RSSFeed.php glpi-project glpi CVE-2024-45610 GLPI has a reflected XSS in ajax/cable.php glpi-project glpi CVE-2024-45609 GLPI has a Reflected XSS in /front/stat.graph.php glpi-project glpi CVE-2024-45608 GLPI has an Authenticated SQL Injection glpi-project glpi CVE-2024-43416 GLPI vulnerable to enumeration of users' email addresses by unauthenticated user glpi-project glpi CVE-2024-41679 Authenticated SQL injection in ticket form glpi-project glpi CVE-2024-40638 GLPI allows account takeover via SQL Injection in AJAX scripts glpi-project glpi CVE-2024-38370 GLPI allows API document download without rights glpi-project glpi CVE-2024-37149 GLPI allows remote code execution through the plugin loader glpi-project glpi CVE-2024-37148 GLPI allows account takeover via SQL Injection in AJAX scripts glpi-project glpi CVE-2024-37147 GLPI allows Authenticated File Upload to Restricted Tickets glpi-project glpi CVE-2024-31456 GLPI contains an authenticated SQL injection glpi-project glpi CVE-2024-29889 GLPI contains an SQL injection through the saved searches glpi-project glpi CVE-2024-28241 GlPI-Agent MSI package installation doesn't update folder security profile when using non default installation folder glpi-project glpi-agent CVE-2024-28240 GLPI-Agent's MSI package installation permits local users to change Agent configuration glpi-project glpi-agent CVE-2024-27930 Sensitive fields access through dropdowns in GLPI glpi-project glpi CVE-2024-27914 Reflected Cross-Site Scripting (XSS) in search engine when debug mode is enabled in GLPI glpi-project glpi CVE-2024-27098 Blind Server-Side Request Forgery (SSRF) using Arbitrary Object Instantiation in GLPI glpi-project glpi CVE-2024-27096 SQL Injection in through the search engine glpi-project glpi CVE-2023-53943 GLPI 9.5.7 Username Enumeration Vulnerability via Lost Password Endpoint Glpi-Project GLPI CVE-2023-51446 GLPI LDAP Injection during authentication glpi-project glpi CVE-2023-46727 GLPI SQL injection through inventory agent request glpi-project glpi CVE-2023-46726 GLPI Remote code execution from LDAP server configuration form on PHP 7.4 glpi-project glpi CVE-2023-42802 GLPI vulnerable to unallowed PHP script execution glpi-project glpi CVE-2023-42462 File deletion through document upload process in GLPI glpi-project glpi CVE-2023-41888 Phishing through a login page malicious URL in GLPI glpi-project glpi CVE-2023-41326 Account takeover via Kanban feature in GLPI glpi-project glpi CVE-2023-41323 Users login enumeration by unauthenticated user in GLPI glpi-project glpi CVE-2023-41322 Privilege Escalation from technician to super-admin in GLPI glpi-project glpi CVE-2023-41321 Sensitive fields enumeration through API in GLPI glpi-project glpi CVE-2023-41320 Account takeover via SQL Injection in UI layout preferences in GLPI glpi-project glpi CVE-2023-37278 GLPI vulnerable to SQL injection via dashboard administration glpi-project glpi CVE-2023-36808 GLPI vulnerable to SQL injection through Computer Virtual Machine information glpi-project glpi CVE-2023-35940 GLPI vulnerable to unauthenticated access to Dashboard data glpi-project glpi CVE-2023-35939 GLPI vulnerable to unauthorized access to Dashboard data glpi-project glpi CVE-2023-35924 GLPI vulnerable to SQL injection via inventory agent request glpi-project glpi CVE-2023-34254 Remote inventory task command injection when using ssh command mode glpi-project glpi-agent CVE-2023-34244 GLPI vulnerable to reflected XSS in search pages glpi-project glpi CVE-2023-34107 GLPI vulnerable to unauthorized access to KnowbaseItem data glpi-project glpi CVE-2023-34106 GLPI vulnerable to unauthorized access to User data glpi-project glpi CVE-2023-28852 GLPI vulnerable to stored Cross-site Scripting through dashboard administration glpi-project glpi CVE-2023-28849 GLPI vulnerable to SQL injection and Stored XSS via inventory agent request glpi-project glpi CVE-2023-28838 GLPI vulnerable to SQL injection through dynamic reports glpi-project glpi CVE-2023-28636 GLPI vulnerable to stored Cross-site Scripting in external links glpi-project glpi CVE-2023-28634 GLPI vulnerable to Privilege Escalation from Technician to Super-Admin glpi-project glpi CVE-2023-28633 GLPI vulnerable to Blind Server-Side Request Forgery (SSRF) in RSS feeds glpi-project glpi CVE-2023-28632 GLPI vulnerable to account takeover by authenticated user glpi-project glpi CVE-2023-23610 glpi vulnerable to Unauthorized access to data export glpi-project glpi CVE-2023-22725 glpi vulnerable to XSS on external links glpi-project glpi CVE-2023-22724 glpi contains XSS in RSS Description Link glpi-project glpi CVE-2023-22722 glpi subject to Cross-site Scripting (XSS) - Reflected glpi-project glpi CVE-2023-22500 glpi Unauthorized access to inventory files glpi-project glpi CVE-2022-41941 glpi contains XSS Stored inside Standard Interface Help Link href attribute glpi-project glpi CVE-2022-39376 Improper input validation on emails links in GLPI glpi-project glpi CVE-2022-39375 Cross-Site Scripting (XSS) through public RSS feed in GLPI glpi-project glpi CVE-2022-39373 Stored Cross-Site Scripting (XSS) in entity name in GLPI glpi-project glpi CVE-2022-39372 Stored Cross-Site Scripting (XSS) in user information in GLPI glpi-project glpi CVE-2022-39371 Stored Cross-Site Scripting (XSS) through asset inventory in GLPI glpi-project glpi CVE-2022-39277 Cross-Site Scripting (XSS) in external links in GLPI glpi-project glpi CVE-2022-39276 Blind Server-Side Request Forgery (SSRF) in RSS feeds and planning glpi-project glpi CVE-2022-39262 Stored Cross-Site Scripting (XSS) on login page in GLPI glpi-project glpi CVE-2022-39234 user session persists even after permanently deleting account in GLPI glpi-project glpi CVE-2022-36112 Blind Server-Side Request Forgery (SSRF) in GLPI glpi-project glpi CVE-2022-35946 SQL injection through plugin controller in GLPI glpi-project glpi CVE-2022-35945 Cross site scripting (XSS) via registration API in GLPI glpi-project glpi CVE-2022-31187 Stored Cross Site Scripting (XSS) through global search in GLPI glpi-project glpi CVE-2022-31143 Leak of sensitive information through login page error in GLPI glpi-project glpi CVE-2022-31082 SQL Injection via package deployment tasks in glpi-inventory-plugin glpi-project glpi-inventory-plugin CVE-2022-31068 Sensitive Data Exposure on Refused Inventory Files in GLPI glpi-project glpi CVE-2022-31062 Unauthenticated Local File Inclusion glpi-project glpi-inventory-plugin CVE-2022-31056 SQL injection with _actor parameter in GLPI glpi-project glpi CVE-2022-24876 Stored cross site scrpting in GLPI's Kanban glpi-project glpi CVE-2022-24868 Cross site scripting via SVG file upload in GLPI glpi-project glpi CVE-2021-39213 IP restriction on GLPI API Bypass with custom header injection glpi-project glpi CVE-2021-39211 Disclosure of GLPI and server information in telemetry endpoint glpi-project glpi CVE-2021-21327 Unsafe Reflection in getItemForItemtype() glpi-project glpi CVE-2021-21324 Insecure Direct Object Reference (IDOR) on "Solutions" glpi-project glpi CVE-2020-5248 Public GLPIKEY can be used to decrypt any data in GLPI glpi-project glpi CVE-2020-26212 Any GLPI CalDAV calendars is read-only for every authenticated user glpi-project glpi CVE-2020-11033 Able to read any token through API user endpoint in GLPI glpi-project GLPI CVE-2020-11032 SQL injection on addme_observer and addme_assign in GLPI glpi-project GLPI 169 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.