Vulnerabilities in Glpi-Project
182 resultsCVE-2024-27930MEDIUMSensitive fields access through dropdowns in GLPIEPSS 1.1%CVE-2023-42802CRITICALGLPI vulnerable to unallowed PHP script executionEPSS 1.1%CVE-2021-39213MEDIUMIP restriction on GLPI API Bypass with custom header injectionEPSS 1.1%CVE-2022-31082MEDIUMSQL Injection via package deployment tasks in glpi-inventory-pluginEPSS 1.0%CVE-2020-11033MEDIUMAble to read any token through API user endpoint in GLPIEPSS 1.0%CVE-2020-15226MEDIUMSQL Injection in GLPI Search APIEPSS 1.0%CVE-2026-53629HIGHGLPI: SQL injection in history tabEPSS 1.0%CVE-2020-11032HIGHSQL injection on addme_observer and addme_assign in GLPIEPSS 1.0%CVE-2021-39210MEDIUMAutologin cookie accessible by scriptsEPSS 1.0%CVE-2020-15217MEDIUMUser data exposure in GLPIEPSS 1.0%CVE-2022-31068MEDIUMSensitive Data Exposure on Refused Inventory Files in GLPIEPSS 0.9%CVE-2023-41321MEDIUMSensitive fields enumeration through API in GLPIEPSS 0.9%CVE-2023-41322MEDIUMPrivilege Escalation from technician to super-admin in GLPIEPSS 0.9%CVE-2021-21313MEDIUMXSS on tabsEPSS 0.9%CVE-2023-41324HIGHAccount takeover through API in GLPIEPSS 0.9%CVE-2024-23645MEDIUMGLPI reflected XSS in reports pagesEPSS 0.9%CVE-2022-35946MEDIUMSQL injection through plugin controller in GLPIEPSS 0.9%CVE-2023-51446MEDIUMGLPI LDAP Injection during authenticationEPSS 0.9%CVE-2022-31143MEDIUMLeak of sensitive information through login page error in GLPIEPSS 0.9%CVE-2021-21255MEDIUMentities switch IDOREPSS 0.9%