Vulnerabilidades em glpi-project

169 resultados
Análise Vexday

Com 167 CVEs catalogadas e nenhuma confirmada em exploração ativa no catálogo KEV da CISA, o glpi-project apresenta taxa de exploração abaixo da média geral do catálogo, o que não elimina o risco considerando o volume total e a velocidade de novos registros — 13 vulnerabilidades surgiram nos últimos 90 dias. A falha mais comum é CWE-79 (Cross-Site Scripting), padrão recorrente em aplicações web de gestão, e o ponto de maior atenção imediata é CVE-2025-24799, que registra EPSS de 0,8618 — indicando alta probabilidade estimada de exploração em curto prazo — e deve ser priorizada nas equipes de resposta. Das 8 CVEs críticas catalogadas, 4 possuem prova de conceito pública disponível, o que reduz a barreira técnica para tentativas de exploração e exige atenção redobrada em ambientes que não aplicaram as correções correspondentes.

CVE-2025-24799HIGHGLPI allows unauthenticated SQL injection through the inventory endpointEPSS 86.1%CVE-2020-15175HIGHUnauthenticated File Deletion in GLPIEPSS 71.4%CVE-2023-46727HIGHGLPI SQL injection through inventory agent requestEPSS 67.5%CVE-2024-29889HIGHGLPI contains an SQL injection through the saved searchesEPSS 63.0%CVE-2024-31456HIGHGLPI contains an authenticated SQL injectionEPSS 59.1%CVE-2024-27096HIGHSQL Injection in through the search engineEPSS 58.8%CVE-2022-31061CRITICALSQL injection on login page in GLPIEPSS 50.9%CVE-2023-35924HIGHGLPI vulnerable to SQL injection via inventory agent requestEPSS 50.7%CVE-2023-36808HIGHGLPI vulnerable to SQL injection through Computer Virtual Machine informationEPSS 47.8%CVE-2024-40638HIGHGLPI allows account takeover via SQL Injection in AJAX scriptsEPSS 36.7%CVE-2024-27098MEDIUMBlind Server-Side Request Forgery (SSRF) using Arbitrary Object Instantiation in GLPIEPSS 35.7%CVE-2022-39323HIGHSQL Injection on REST API in GLPIEPSS 34.3%CVE-2023-41323MEDIUMUsers login enumeration by unauthenticated user in GLPIEPSS 33.9%CVE-2023-41320HIGHAccount takeover via SQL Injection in UI layout preferences in GLPIEPSS 31.9%CVE-2023-41326HIGHAccount takeover via Kanban feature in GLPIEPSS 31.0%CVE-2023-43813MEDIUMglpi Authenticated SQL InjectionEPSS 30.9%CVE-2024-27937MEDIUMglpi Users emails enumerationEPSS 26.9%CVE-2024-37149HIGHGLPI allows remote code execution through the plugin loaderEPSS 21.1%CVE-2024-37148HIGHGLPI allows account takeover via SQL Injection in AJAX scriptsEPSS 20.2%CVE-2024-50339CRITICALGLPI vulnerable to unauthenticated session hijackingEPSS 19.6%