Vulnerabilidades em Glpi-Project
182 resultadosAnálise Vexday
GLPI-Project apresenta um perfil de risco baixo com apenas 1 vulnerabilidade catalogada e nenhuma sob exploração ativa confirmada. A fraqueza identificada (CWE-203 - Observação de Diferenças de Informações) não é classificada como crítica e não gerou novos registros nos últimos 90 dias, indicando que o risco é estável e historicamente contido.
CVE-2026-26001HIGHGLPI Inventory Plugin has SQL Injection on dropdown_calendar ReportEPSS 0.4%CVE-2025-53105HIGHGLPI permits unauthorized rules execution orderEPSS 0.4%CVE-2025-21627MEDIUMGLPI Cross-site Scripting vulnerabilityEPSS 0.4%CVE-2026-49470HIGHGLPI: Missing Rate Limiting on Login and TOTP Verification — Account Takeover via Brute ForceEPSS 0.4%CVE-2024-43417MEDIUMReflected XSS in Software formEPSS 0.4%CVE-2026-22247MEDIUMGLPI is Vulnerable to SSRF via WebhooksEPSS 0.4%CVE-2024-38370MEDIUMGLPI allows API document download without rightsEPSS 0.4%CVE-2023-53943MEDIUMGLPI 9.5.7 Username Enumeration Vulnerability via Lost Password EndpointEPSS 0.4%CVE-2025-26626MEDIUMGLPI Inventory Plugin vulnerable to reflective Cross-site ScriptingEPSS 0.3%CVE-2024-45610MEDIUMGLPI has a reflected XSS in ajax/cable.phpEPSS 0.3%CVE-2024-45609MEDIUMGLPI has a Reflected XSS in /front/stat.graph.phpEPSS 0.3%CVE-2026-48482CRITICALGLPI: RCE via Form importEPSS 0.3%CVE-2020-11031HIGHInsecure encryption algorithm in GLPIEPSS 0.3%CVE-2026-47679HIGHGLPI: arbitrary file deletionEPSS 0.3%CVE-2025-64516HIGHGLPI incorrectly authorizes access to documentsEPSS 0.3%CVE-2026-25932HIGHGLPI has Stored XSS in Supplier 'Website' fieldEPSS 0.3%CVE-2026-22248HIGHGLPI affected by Remote Code Execution via malicious uploadEPSS 0.3%CVE-2026-45801MEDIUMGLPI: Unauthorized Debug Mode Activation via Profile Update (Privilege Escalation)EPSS 0.3%CVE-2026-55217MEDIUMGLPI: Unallowed modfication of knowbase items comments and translationsEPSS 0.3%CVE-2026-40108HIGHGLPI Vulnerable to Stored XSS in ITIL CostsEPSS 0.3%