Vulnerabilities in Glpi-Project

182 results
CVE-2021-39209HIGHBypassable CSRF protectionEPSS 0.5%CVE-2024-45608MEDIUMGLPI has an Authenticated SQL InjectionEPSS 0.5%CVE-2024-41679MEDIUMAuthenticated SQL injection in ticket formEPSS 0.5%CVE-2022-39375MEDIUMCross-Site Scripting (XSS) through public RSS feed in GLPIEPSS 0.5%CVE-2022-24876MEDIUMStored cross site scrpting in GLPI's KanbanEPSS 0.5%CVE-2024-47761HIGHGLPI vulnerable to account takeover via the password reset featureEPSS 0.5%CVE-2022-39376LOWImproper input validation on emails links in GLPIEPSS 0.5%CVE-2023-34244MEDIUMGLPI vulnerable to reflected XSS in search pagesEPSS 0.5%CVE-2024-41678MEDIUMGLPI has multiple reflected XSSEPSS 0.5%CVE-2023-28849CRITICALGLPI vulnerable to SQL injection and Stored XSS via inventory agent requestEPSS 0.5%CVE-2023-41888MEDIUMPhishing through a login page malicious URL in GLPIEPSS 0.5%CVE-2023-28633LOWGLPI vulnerable to Blind Server-Side Request Forgery (SSRF) in RSS feedsEPSS 0.5%CVE-2025-66417HIGHGLPI has an unauthenticated SQL injection through the inventory endpointEPSS 0.5%CVE-2024-47760HIGHGLPI vulnerable to account takeover via APIEPSS 0.5%CVE-2022-39371HIGHStored Cross-Site Scripting (XSS) through asset inventory in GLPIEPSS 0.5%CVE-2022-39373MEDIUMStored Cross-Site Scripting (XSS) in entity name in GLPIEPSS 0.5%CVE-2022-39370MEDIUMImproper access to debug panel in GLPIEPSS 0.5%CVE-2024-47758HIGHGLPI vulnerable to account takeover without privilege escalation through the APIEPSS 0.5%CVE-2026-13490MEDIUMglpi-project glpi Document document.send.php canViewFile authorizationEPSS 0.5%CVE-2025-23046MEDIUMGLPI vulnerable to unauthorized authentication by email using the OAuthIMAP pluginEPSS 0.5%