Vulnerabilities in Glpi-Project
169 resultsVexday analysis
GLPI-Project apresenta um perfil de risco baixo com apenas 1 vulnerabilidade catalogada e nenhuma sob exploração ativa confirmada. A fraqueza identificada (CWE-203 - Observação de Diferenças de Informações) não é classificada como crítica e não gerou novos registros nos últimos 90 dias, indicando que o risco é estável e historicamente contido.
CVE-2024-47759MEDIUMGLPI has a stored XSS via document uploadEPSS 0.4%CVE-2025-27147HIGHGLPI Inventory plugin has Improper Access Control VulnerabilityEPSS 0.4%CVE-2022-39372LOWStored Cross-Site Scripting (XSS) in user information in GLPIEPSS 0.4%CVE-2025-21619HIGHGLPI allows SQL injection through the rules configurationEPSS 0.4%CVE-2024-43418MEDIUMGLPI has multiple reflected XSSEPSS 0.4%CVE-2026-29047HIGHGLPI has an Authenticated SQL Injection via log exportsEPSS 0.4%CVE-2022-39234MEDIUMuser session persists even after permanently deleting account in GLPIEPSS 0.4%CVE-2026-23624MEDIUMGLPI is vulnerable to session stealing on externally authenticated user changeEPSS 0.4%CVE-2025-53105HIGHGLPI permits unauthorized rules execution orderEPSS 0.4%CVE-2024-43417MEDIUMReflected XSS in Software formEPSS 0.4%CVE-2024-38370MEDIUMGLPI allows API document download without rightsEPSS 0.4%CVE-2025-21627MEDIUMGLPI Cross-site Scripting vulnerabilityEPSS 0.3%CVE-2026-42317HIGHGLPI vulnerable to arbitrary files deletion by technicianEPSS 0.3%CVE-2026-42321HIGHGLPI has stored XSS in asset locksEPSS 0.3%CVE-2026-25936MEDIUMGLPI Vulnerable to Authenticated SQL InjectionEPSS 0.3%CVE-2024-45609MEDIUMGLPI has a Reflected XSS in /front/stat.graph.phpEPSS 0.3%CVE-2024-45610MEDIUMGLPI has a reflected XSS in ajax/cable.phpEPSS 0.3%CVE-2025-26626MEDIUMGLPI Inventory Plugin vulnerable to reflective Cross-site ScriptingEPSS 0.3%CVE-2020-11031HIGHInsecure encryption algorithm in GLPIEPSS 0.3%CVE-2026-22247MEDIUMGLPI is Vulnerable to SSRF via WebhooksEPSS 0.3%