Vulnerabilidades em Glpi-Project
182 resultadosAnálise Vexday
GLPI-Project apresenta um perfil de risco baixo com apenas 1 vulnerabilidade catalogada e nenhuma sob exploração ativa confirmada. A fraqueza identificada (CWE-203 - Observação de Diferenças de Informações) não é classificada como crítica e não gerou novos registros nos últimos 90 dias, indicando que o risco é estável e historicamente contido.
CVE-2024-45611MEDIUMGLPI has a stored XSS at src/RSSFeed.phpEPSS 0.3%CVE-2026-53627MEDIUMGLPI: Unexpected access to update operations through the APIEPSS 0.3%CVE-2026-22044MEDIUMGLPI is Vulnerable to Authenticated SQL InjectionEPSS 0.3%CVE-2026-53626HIGHGLPI: Arbitrary Document Read via Form Context Authorization BypassEPSS 0.3%CVE-2026-42320MEDIUMGLPI vulnerable to arbitrary file accessEPSS 0.3%CVE-2025-59935MEDIUMGLPI Vulnerable to Unauthenticated Stored XSS on the Inventory pageEPSS 0.3%CVE-2026-32312MEDIUMGLPI: Unauthorized export of form structureEPSS 0.3%CVE-2025-23024MEDIUMGLPI: Plugins are disabled accessing one pageEPSS 0.3%CVE-2026-26027HIGHGLPI has an Unauthenticated Stored XSS via inventoryEPSS 0.3%CVE-2026-25590MEDIUMGLPI Inventory Plugin has Reflected XSS in task jobsEPSS 0.3%CVE-2026-55214HIGHGLPI: Stored XSS in suppliersEPSS 0.3%CVE-2025-53111MEDIUMGLPI exposes data to non-allowed usersEPSS 0.3%CVE-2025-53008MEDIUMGLPI's MailCollector Receiver is vulnerable to credential exfiltrationEPSS 0.3%CVE-2025-53113LOWGLPI technicians can access unauthorized information through external linksEPSS 0.2%CVE-2024-28240HIGHGLPI-Agent's MSI package installation permits local users to change Agent configurationEPSS 0.2%CVE-2024-28241HIGHGlPI-Agent MSI package installation doesn't update folder security profile when using non default installation folderEPSS 0.2%CVE-2025-64520MEDIUMGLPI vulnerable to unauthorized access to restricted Knowledge Base items through the APIEPSS 0.2%CVE-2025-52897MEDIUMGLPI is vulnerable to XSS and open redirection attacks through planning featureEPSS 0.2%CVE-2025-53112MEDIUMGLPI's incomprehensive permission checks can lead to data removal from allowed usersEPSS 0.2%CVE-2025-27514MEDIUMGLPI is susceptible to Stored XSS attack through project's kanbanEPSS 0.2%