CVE-2026-25937
- EPSS 0.01%
- Veröffentlicht 17.03.2026 23:16:38
- Zuletzt bearbeitet 23.03.2026 18:16:40
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor with knowledge of a user's credentials can bypass MFA and steal their account. Version 11.0.6 fixes the issue.
CVE-2026-25936
- EPSS 0.04%
- Veröffentlicht 17.03.2026 19:41:32
- Zuletzt bearbeitet 19.03.2026 19:30:14
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injection. Version 11.0.6 fixes the issue.
CVE-2026-22248
- EPSS 0.2%
- Veröffentlicht 11.03.2026 15:27:04
- Zuletzt bearbeitet 20.03.2026 14:29:50
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. From 11.0.0 to before 11.0.5, an authenticated technician user can upload a malicious file and trigger ...
CVE-2026-22044
- EPSS 0.04%
- Veröffentlicht 04.02.2026 17:15:39
- Zuletzt bearbeitet 06.02.2026 21:19:53
GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This issue has been patched in version 10.0.23.
CVE-2026-23624
- EPSS 0.12%
- Veröffentlicht 04.02.2026 17:15:33
- Zuletzt bearbeitet 06.02.2026 21:18:17
GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO variables, a user can steal a GLPI session previously opened by another user...
CVE-2026-22247
- EPSS 0.02%
- Veröffentlicht 04.02.2026 17:10:30
- Zuletzt bearbeitet 06.02.2026 21:19:00
GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issue has been patched in version 11.0.5.
CVE-2025-66417
- EPSS 0.05%
- Veröffentlicht 15.01.2026 16:25:03
- Zuletzt bearbeitet 21.01.2026 20:54:11
GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.
CVE-2025-64516
- EPSS 0.05%
- Veröffentlicht 15.01.2026 16:01:03
- Zuletzt bearbeitet 21.01.2026 20:53:37
GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthorized access can be performed by...
CVE-2023-53943
- EPSS 0.05%
- Veröffentlicht 18.12.2025 19:53:36
- Zuletzt bearbeitet 31.12.2025 17:34:30
GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email addresses by submitting requests to the password reset endpoin...
CVE-2025-64520
- EPSS 0.04%
- Veröffentlicht 16.12.2025 21:59:02
- Zuletzt bearbeitet 19.02.2026 16:20:09
GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to 10.0.21 to receive a patch.