Vulnerabilities in Glpi-Project
169 resultsVexday analysis
GLPI-Project apresenta um perfil de risco baixo com apenas 1 vulnerabilidade catalogada e nenhuma sob exploração ativa confirmada. A fraqueza identificada (CWE-203 - Observação de Diferenças de Informações) não é classificada como crítica e não gerou novos registros nos últimos 90 dias, indicando que o risco é estável e historicamente contido.
CVE-2025-52897MEDIUMGLPI is vulnerable to XSS and open redirection attacks through planning featureEPSS 0.2%CVE-2026-26001HIGHGLPI Inventory Plugin has SQL Injection on dropdown_calendar ReportEPSS 0.2%CVE-2025-53112MEDIUMGLPI's incomprehensive permission checks can lead to data removal from allowed usersEPSS 0.2%CVE-2025-64520MEDIUMGLPI vulnerable to unauthorized access to restricted Knowledge Base items through the APIEPSS 0.2%CVE-2025-27514MEDIUMGLPI is susceptible to Stored XSS attack through project's kanbanEPSS 0.2%CVE-2026-26027HIGHGLPI has an Unauthenticated Stored XSS via inventoryEPSS 0.2%CVE-2025-52567LOWGLPI has overly permissive URL verificationEPSS 0.2%CVE-2025-53357MEDIUMGLPI permits reservation modification by unauthorized usersEPSS 0.2%CVE-2026-25590MEDIUMGLPI Inventory Plugin has Reflected XSS in task jobsEPSS 0.2%