Vulnerabilities in Glpi-Project

182 results
CVE-2026-53628MEDIUMGLPI: Unallowed authentication method update by administratorEPSS 0.5%CVE-2026-25936MEDIUMGLPI Vulnerable to Authenticated SQL InjectionEPSS 0.4%CVE-2026-29047HIGHGLPI has an Authenticated SQL Injection via log exportsEPSS 0.4%CVE-2024-48912HIGHGLPI vulnerable to authenticated insecure account deletionEPSS 0.4%CVE-2022-39372LOWStored Cross-Site Scripting (XSS) in user information in GLPIEPSS 0.4%CVE-2025-21626MEDIUMGLPI vulnerable to exposure of sensitive information in the `status.php` endpointEPSS 0.4%CVE-2025-27147HIGHGLPI Inventory plugin has Improper Access Control VulnerabilityEPSS 0.4%CVE-2026-23624MEDIUMGLPI is vulnerable to session stealing on externally authenticated user changeEPSS 0.4%CVE-2025-21619HIGHGLPI allows SQL injection through the rules configurationEPSS 0.4%CVE-2024-47759MEDIUMGLPI has a stored XSS via document uploadEPSS 0.4%CVE-2026-42317HIGHGLPI vulnerable to arbitrary files deletion by technicianEPSS 0.4%CVE-2026-42321HIGHGLPI has stored XSS in asset locksEPSS 0.4%CVE-2022-39234MEDIUMuser session persists even after permanently deleting account in GLPIEPSS 0.4%CVE-2026-42318HIGHGLPI Vulnerable to Arbitrary Item Deletion via Planning EndpointEPSS 0.4%CVE-2026-26263HIGHGLPI has an Unauthenticated SQL Injection via Search engineEPSS 0.4%CVE-2024-43418MEDIUMGLPI has multiple reflected XSSEPSS 0.4%CVE-2026-49469MEDIUMGLPI: LDAP filter injection in user import featureEPSS 0.4%CVE-2026-25937MEDIUMGLPI has a MFA bypassEPSS 0.4%CVE-2026-53610HIGHGLPI: Reflected XSS in dashboardsEPSS 0.4%CVE-2026-44281HIGHGLPI vulnerable to unauthorized reading of a specific asset objectEPSS 0.4%