Vulnerabilidades en glpi-project

169 resultados
Análisis Vexday

Com 167 CVEs catalogadas e nenhuma confirmada em exploração ativa no catálogo KEV da CISA, o glpi-project apresenta taxa de exploração abaixo da média geral do catálogo, o que não elimina o risco considerando o volume total e a velocidade de novos registros — 13 vulnerabilidades surgiram nos últimos 90 dias. A falha mais comum é CWE-79 (Cross-Site Scripting), padrão recorrente em aplicações web de gestão, e o ponto de maior atenção imediata é CVE-2025-24799, que registra EPSS de 0,8618 — indicando alta probabilidade estimada de exploração em curto prazo — e deve ser priorizada nas equipes de resposta. Das 8 CVEs críticas catalogadas, 4 possuem prova de conceito pública disponível, o que reduz a barreira técnica para tentativas de exploração e exige atenção redobrada em ambientes que não aplicaram as correções correspondentes.

CVE-2024-41679MEDIUMAuthenticated SQL injection in ticket formEPSS 0.5%CVE-2022-39375MEDIUMCross-Site Scripting (XSS) through public RSS feed in GLPIEPSS 0.5%CVE-2024-47761HIGHGLPI vulnerable to account takeover via the password reset featureEPSS 0.5%CVE-2022-24876MEDIUMStored cross site scrpting in GLPI's KanbanEPSS 0.5%CVE-2022-39376LOWImproper input validation on emails links in GLPIEPSS 0.5%CVE-2023-34244MEDIUMGLPI vulnerable to reflected XSS in search pagesEPSS 0.5%CVE-2024-41678MEDIUMGLPI has multiple reflected XSSEPSS 0.5%CVE-2023-28849CRITICALGLPI vulnerable to SQL injection and Stored XSS via inventory agent requestEPSS 0.5%CVE-2023-28633LOWGLPI vulnerable to Blind Server-Side Request Forgery (SSRF) in RSS feedsEPSS 0.5%CVE-2025-66417HIGHGLPI has an unauthenticated SQL injection through the inventory endpointEPSS 0.5%CVE-2024-47760HIGHGLPI vulnerable to account takeover via APIEPSS 0.5%CVE-2022-39371HIGHStored Cross-Site Scripting (XSS) through asset inventory in GLPIEPSS 0.5%CVE-2022-39373MEDIUMStored Cross-Site Scripting (XSS) in entity name in GLPIEPSS 0.5%CVE-2022-39370MEDIUMImproper access to debug panel in GLPIEPSS 0.5%CVE-2026-13490MEDIUMglpi-project glpi Document document.send.php canViewFile authorizationEPSS 0.5%CVE-2024-47758HIGHGLPI vulnerable to account takeover without privilege escalation through the APIEPSS 0.5%CVE-2025-23046MEDIUMGLPI vulnerable to unauthorized authentication by email using the OAuthIMAP pluginEPSS 0.5%CVE-2024-48912HIGHGLPI vulnerable to authenticated insecure account deletionEPSS 0.4%CVE-2022-39372LOWStored Cross-Site Scripting (XSS) in user information in GLPIEPSS 0.4%CVE-2025-21626MEDIUMGLPI vulnerable to exposure of sensitive information in the `status.php` endpointEPSS 0.4%