- Products & ServicesProducts & Services
- SolutionsSolutions
- PricingPricing
- CompanyCompany
- ResourcesResources
en
en
As of 09/13/2026, glpi-project recorded 1 security vulnerabilities in the last 90 days across 1 products, including 0 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, glpi had the most security vulnerabilities in the glpi-project ecosystem, with 1 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-13490glpi-project glpi Document document.send.php canViewFile authorization | Exploitation statusPublic exploit | FixNot confirmed | Affected productglpi | Published06/28/2026 | SeverityMedium |
CVE-2026-42321GLPI has stored XSS in asset locks | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published06/03/2026 | SeverityHigh |
CVE-2026-42320GLPI vulnerable to arbitrary file access | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published06/03/2026 | SeverityMedium |
CVE-2026-42318GLPI Vulnerable to Arbitrary Item Deletion via Planning Endpoint | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published06/03/2026 | SeverityHigh |
CVE-2026-42317GLPI vulnerable to arbitrary files deletion by technician | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published06/03/2026 | SeverityHigh |
CVE-2026-44281GLPI vulnerable to unauthorized reading of a specific asset object | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published06/03/2026 | SeverityHigh |
CVE-2026-40108GLPI Vulnerable to Stored XSS in ITIL Costs | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published06/02/2026 | SeverityHigh |
CVE-2026-5385GLPI 11.0.0 - Stored XSS in knowledge base | Exploitation statusPublic exploit | FixYes | Affected productglpi | Published06/02/2026 | SeverityHigh |
CVE-2026-32312GLPI: Unauthorized export of form structure | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published05/18/2026 | SeverityMedium |
CVE-2026-29047GLPI has an Authenticated SQL Injection via log exports | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published04/06/2026 | SeverityHigh |
CVE-2026-26263GLPI has an Unauthenticated SQL Injection via Search engine | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published04/06/2026 | SeverityHigh |
CVE-2026-26027GLPI has an Unauthenticated Stored XSS via inventory | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published04/06/2026 | SeverityHigh |
CVE-2026-26026GLPI has a Server-Side Template Injection via Double-Compilation | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published04/06/2026 | SeverityCritical |
CVE-2026-25932GLPI has Stored XSS in Supplier 'Website' field | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published04/06/2026 | SeverityHigh |
CVE-2026-26001GLPI Inventory Plugin has SQL Injection on dropdown_calendar Report | Exploitation statusNot known exploited | FixYes | Affected productglpi-inventory-plugin | Published03/17/2026 | SeverityHigh |
CVE-2026-25937GLPI has a MFA bypass | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published03/17/2026 | SeverityMedium |
CVE-2026-25936GLPI Vulnerable to Authenticated SQL Injection | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published03/17/2026 | SeverityMedium |
CVE-2026-22248GLPI affected by Remote Code Execution via malicious upload | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published03/11/2026 | SeverityHigh |
CVE-2026-25590GLPI Inventory Plugin has Reflected XSS in task jobs | Exploitation statusNot known exploited | FixYes | Affected productglpi-inventory-plugin | Published03/03/2026 | SeverityMedium |
CVE-2026-22821mreporting affected by a SQLI on date change | Exploitation statusNot known exploited | FixYes | Affected productmreporting | Published02/12/2026 | SeverityMedium |
CVE-2026-22044GLPI is Vulnerable to Authenticated SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published02/04/2026 | SeverityMedium |
CVE-2026-23624GLPI is vulnerable to session stealing on externally authenticated user change | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published02/04/2026 | SeverityMedium |
CVE-2026-22247GLPI is Vulnerable to SSRF via Webhooks | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published02/04/2026 | SeverityMedium |
CVE-2025-66417GLPI has an unauthenticated SQL injection through the inventory endpoint | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published01/15/2026 | SeverityHigh |
CVE-2025-64516GLPI incorrectly authorizes access to documents | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published01/15/2026 | SeverityHigh |
CVE-2023-53943GLPI 9.5.7 Username Enumeration Vulnerability via Lost Password Endpoint | Exploitation statusPublic exploit | FixNot confirmed | Affected productglpi | Published12/18/2025 | SeverityMedium |
CVE-2025-64520GLPI vulnerable to unauthorized access to restricted Knowledge Base items through the API | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published12/16/2025 | SeverityMedium |
CVE-2025-59935GLPI Vulnerable to Unauthenticated Stored XSS on the Inventory page | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published12/16/2025 | SeverityMedium |
CVE-2025-32786GLPI Inventory Plugin is Vulnerable to Unauthenticated SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productglpi-inventory-plugin | Published11/04/2025 | SeverityHigh |
CVE-2025-53105GLPI permits unauthorized rules execution order | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published08/27/2025 | SeverityHigh |
CVE-2025-53357GLPI permits reservation modification by unauthorized users | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published07/30/2025 | SeverityMedium |
CVE-2025-53113GLPI technicians can access unauthorized information through external links | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published07/30/2025 | SeverityLow |
CVE-2025-53112GLPI's incomprehensive permission checks can lead to data removal from allowed users | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published07/30/2025 | SeverityMedium |
CVE-2025-53111GLPI exposes data to non-allowed users | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published07/30/2025 | SeverityMedium |
CVE-2025-53008GLPI's MailCollector Receiver is vulnerable to credential exfiltration | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published07/30/2025 | SeverityMedium |
CVE-2025-52897GLPI is vulnerable to XSS and open redirection attacks through planning feature | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published07/30/2025 | SeverityMedium |
CVE-2025-52567GLPI has overly permissive URL verification | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published07/30/2025 | SeverityLow |
CVE-2025-27514GLPI is susceptible to Stored XSS attack through project's kanban | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published07/29/2025 | SeverityMedium |
CVE-2025-27147GLPI Inventory plugin has Improper Access Control Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi-inventory-plugin | Published03/25/2025 | SeverityHigh |
CVE-2025-24801GLPI allows authenticated remote code execution | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published03/18/2025 | SeverityHigh |
CVE-2025-24799GLPI allows unauthenticated SQL injection through the inventory endpoint | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published03/18/2025 | SeverityHigh |
CVE-2025-21619GLPI allows SQL injection through the rules configuration | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published03/18/2025 | SeverityHigh |
CVE-2025-26626GLPI Inventory Plugin vulnerable to reflective Cross-site Scripting | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi-inventory-plugin | Published03/14/2025 | SeverityMedium |
CVE-2025-25192GLPI allows unauthorized access to debug mode | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published02/25/2025 | SeverityMedium |
CVE-2025-23046GLPI vulnerable to unauthorized authentication by email using the OAuthIMAP plugin | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published02/25/2025 | SeverityMedium |
CVE-2025-23024GLPI: Plugins are disabled accessing one page | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published02/25/2025 | SeverityMedium |
CVE-2025-21627GLPI Cross-site Scripting vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published02/25/2025 | SeverityMedium |
CVE-2025-21626GLPI vulnerable to exposure of sensitive information in the `status.php` endpoint | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published02/25/2025 | SeverityMedium |
CVE-2024-11955GLPI index.php redirect | Exploitation statusPublic exploit | FixYes | Affected productGLPI | Published02/25/2025 | SeverityMedium |
CVE-2024-50339GLPI vulnerable to unauthenticated session hijacking | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published12/11/2024 | SeverityCritical |
CVE-2024-48912GLPI vulnerable to authenticated insecure account deletion | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published12/11/2024 | SeverityHigh |
CVE-2024-47761GLPI vulnerable to account takeover via the password reset feature | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published12/11/2024 | SeverityHigh |
CVE-2024-47760GLPI vulnerable to account takeover via API | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published12/11/2024 | SeverityHigh |
CVE-2024-47758GLPI vulnerable to account takeover without privilege escalation through the API | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published12/11/2024 | SeverityHigh |
CVE-2024-43416GLPI vulnerable to enumeration of users' email addresses by unauthenticated user | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published11/18/2024 | SeverityHigh |
CVE-2024-38370GLPI allows API document download without rights | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published11/15/2024 | SeverityMedium |
CVE-2024-45611GLPI has a stored XSS at src/RSSFeed.php | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published11/15/2024 | SeverityMedium |
CVE-2024-45610GLPI has a reflected XSS in ajax/cable.php | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published11/15/2024 | SeverityMedium |
CVE-2024-45609GLPI has a Reflected XSS in /front/stat.graph.php | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published11/15/2024 | SeverityMedium |
CVE-2024-45608GLPI has an Authenticated SQL Injection | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published11/15/2024 | SeverityMedium |
CVE-2024-43418GLPI has multiple reflected XSS | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published11/15/2024 | SeverityMedium |
CVE-2024-43417Reflected XSS in Software form | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published11/15/2024 | SeverityMedium |
CVE-2024-41679Authenticated SQL injection in ticket form | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published11/15/2024 | SeverityMedium |
CVE-2024-41678GLPI has multiple reflected XSS | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published11/15/2024 | SeverityMedium |
CVE-2024-40638GLPI allows account takeover via SQL Injection in AJAX scripts | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published11/15/2024 | SeverityHigh |
CVE-2024-47759GLPI has a stored XSS via document upload | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published11/15/2024 | SeverityMedium |
CVE-2024-37149GLPI allows remote code execution through the plugin loader | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published07/10/2024 | SeverityHigh |
CVE-2024-37148GLPI allows account takeover via SQL Injection in AJAX scripts | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published07/10/2024 | SeverityHigh |
CVE-2024-37147GLPI allows Authenticated File Upload to Restricted Tickets | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published07/10/2024 | SeverityMedium |
CVE-2024-31456GLPI contains an authenticated SQL injection | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published05/07/2024 | SeverityHigh |
CVE-2024-29889GLPI contains an SQL injection through the saved searches | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published05/07/2024 | SeverityHigh |
CVE-2024-28241GlPI-Agent MSI package installation doesn't update folder security profile when using non default installation folder | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi-agent | Published04/25/2024 | SeverityHigh |
CVE-2024-28240GLPI-Agent's MSI package installation permits local users to change Agent configuration | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi-agent | Published04/25/2024 | SeverityHigh |
CVE-2024-27914Reflected Cross-Site Scripting (XSS) in search engine when debug mode is enabled in GLPI | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published03/18/2024 | SeverityMedium |
CVE-2024-27104Stored XSS in dashboards in GLPI | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published03/18/2024 | SeverityMedium |
CVE-2024-27098Blind Server-Side Request Forgery (SSRF) using Arbitrary Object Instantiation in GLPI | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published03/18/2024 | SeverityMedium |
CVE-2024-27096SQL Injection in through the search engine | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published03/18/2024 | SeverityHigh |
CVE-2024-27930Sensitive fields access through dropdowns in GLPI | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published03/18/2024 | SeverityMedium |
CVE-2024-27937glpi Users emails enumeration | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published03/18/2024 | SeverityMedium |
CVE-2024-27756 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published03/15/2024 | SeverityHigh |
CVE-2023-51446GLPI LDAP Injection during authentication | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published02/01/2024 | SeverityMedium |
CVE-2024-23645GLPI reflected XSS in reports pages | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published02/01/2024 | SeverityMedium |
CVE-2023-46727GLPI SQL injection through inventory agent request | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published12/13/2023 | SeverityHigh |
CVE-2023-46726GLPI Remote code execution from LDAP server configuration form on PHP 7.4 | Exploitation statusNot confirmed | FixNot confirmed | Affected productglpi | Published12/13/2023 | SeverityHigh |
CVE-2023-43813glpi Authenticated SQL Injection | Exploitation statusNot confirmed | FixNot confirmed | Affected productglpi | Published12/13/2023 | SeverityMedium |
CVE-2023-42802GLPI vulnerable to unallowed PHP script execution | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published11/02/2023 | SeverityCritical |
CVE-2023-42462File deletion through document upload process in GLPI | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published09/26/2023 | SeverityHigh |
CVE-2023-42461SQL injection in ITIL actors in GLPI | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published09/26/2023 | SeverityMedium |
CVE-2023-41888Phishing through a login page malicious URL in GLPI | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published09/26/2023 | SeverityMedium |
CVE-2023-41326Account takeover via Kanban feature in GLPI | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published09/26/2023 | SeverityHigh |
CVE-2023-41324Account takeover through API in GLPI | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published09/26/2023 | SeverityHigh |
CVE-2023-41323Users login enumeration by unauthenticated user in GLPI | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published09/26/2023 | SeverityMedium |
CVE-2023-41322Privilege Escalation from technician to super-admin in GLPI | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published09/26/2023 | SeverityMedium |
CVE-2023-41321Sensitive fields enumeration through API in GLPI | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published09/26/2023 | SeverityMedium |
CVE-2023-41320Account takeover via SQL Injection in UI layout preferences in GLPI | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published09/26/2023 | SeverityHigh |
CVE-2023-37278GLPI vulnerable to SQL injection via dashboard administration | Exploitation statusNot known exploited | FixYes | Affected productglpi | Published07/13/2023 | SeverityMedium |
CVE-2023-36808GLPI vulnerable to SQL injection through Computer Virtual Machine information | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published07/05/2023 | SeverityHigh |
CVE-2023-35940GLPI vulnerable to unauthenticated access to Dashboard data | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published07/05/2023 | SeverityHigh |
CVE-2023-35939GLPI vulnerable to unauthorized access to Dashboard data | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published07/05/2023 | SeverityHigh |
CVE-2023-35924GLPI vulnerable to SQL injection via inventory agent request | Exploitation statusNot known exploited | FixNot confirmed | Affected productglpi | Published07/05/2023 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan