Vulnerabilidades en Glpi-Project
169 resultadosAnálisis Vexday
GLPI-Project apresenta um perfil de risco baixo com apenas 1 vulnerabilidade catalogada e nenhuma sob exploração ativa confirmada. A fraqueza identificada (CWE-203 - Observação de Diferenças de Informações) não é classificada como crítica e não gerou novos registros nos últimos 90 dias, indicando que o risco é estável e historicamente contido.
CVE-2022-39262MEDIUMStored Cross-Site Scripting (XSS) on login page in GLPIEPSS 0.6%CVE-2022-24868HIGHCross site scripting via SVG file upload in GLPIEPSS 0.6%CVE-2023-22722MEDIUMglpi subject to Cross-site Scripting (XSS) - Reflected EPSS 0.6%CVE-2023-22725MEDIUMglpi vulnerable to XSS on external linksEPSS 0.6%CVE-2022-31187MEDIUMStored Cross Site Scripting (XSS) through global search in GLPIEPSS 0.6%CVE-2021-21312MEDIUMStored XSS on documentsEPSS 0.6%CVE-2022-39276LOWBlind Server-Side Request Forgery (SSRF) in RSS feeds and planningEPSS 0.6%CVE-2021-21314MEDIUMXSS injection on ticket updateEPSS 0.6%CVE-2023-28636MEDIUMGLPI vulnerable to stored Cross-site Scripting in external linksEPSS 0.6%CVE-2022-41941MEDIUMglpi contains XSS Stored inside Standard Interface Help Link href attributeEPSS 0.6%CVE-2023-35939HIGHGLPI vulnerable to unauthorized access to Dashboard dataEPSS 0.6%CVE-2023-34106MEDIUMGLPI vulnerable to unauthorized access to User dataEPSS 0.6%CVE-2023-34107MEDIUMGLPI vulnerable to unauthorized access to KnowbaseItem dataEPSS 0.6%CVE-2023-22724MEDIUMglpi contains XSS in RSS Description LinkEPSS 0.6%CVE-2022-35945MEDIUMCross site scripting (XSS) via registration API in GLPIEPSS 0.6%CVE-2022-39277MEDIUMCross-Site Scripting (XSS) in external links in GLPIEPSS 0.5%CVE-2023-28852MEDIUMGLPI vulnerable to stored Cross-site Scripting through dashboard administrationEPSS 0.5%CVE-2021-39209HIGHBypassable CSRF protectionEPSS 0.5%CVE-2024-41679MEDIUMAuthenticated SQL injection in ticket formEPSS 0.5%CVE-2024-45608MEDIUMGLPI has an Authenticated SQL InjectionEPSS 0.5%