CVE-2026-45801
- EPSS 0.31%
- Veröffentlicht 25.09.2026 18:27:33
- Zuletzt bearbeitet 25.09.2026 20:17:06
GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable debug mode. The affected user-setting update does not enforce the privilege boundary intende...
- EPSS 0.31%
- Veröffentlicht 25.09.2026 18:26:37
- Zuletzt bearbeitet 25.09.2026 19:17:28
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that the same user is normally forbidden to perform through the user interfac...
CVE-2026-49469
- EPSS 0.4%
- Veröffentlicht 25.09.2026 18:25:43
- Zuletzt bearbeitet 29.09.2026 18:17:15
GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter. This allows...
CVE-2026-13490
- EPSS 0.31%
- Veröffentlicht 28.06.2026 11:00:05
- Zuletzt bearbeitet 30.06.2026 19:16:27
A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.php of the component Document Handler. Such manipulation of the argument docid leads...
CVE-2026-42321
- EPSS 0.34%
- Veröffentlicht 03.06.2026 15:25:17
- Zuletzt bearbeitet 22.07.2026 19:10:00
GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS payload in the asset locked tab. Upgrade to 10.0.25 or 11.0.7 to receive a patch.
CVE-2026-42320
- EPSS 0.24%
- Veröffentlicht 03.06.2026 15:23:46
- Zuletzt bearbeitet 22.07.2026 19:10:00
GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arbitrary files inside the GLPI_DOC_DIR. Upgrade to 10.0.25 or 11.0.7 to receive a patch.
- EPSS 0.29%
- Veröffentlicht 03.06.2026 15:17:16
- Zuletzt bearbeitet 21.08.2026 20:16:35
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI. Upgrade to 11.0.7 or 10.0.25 to receive a patch. A...
- EPSS 0.35%
- Veröffentlicht 03.06.2026 15:16:02
- Zuletzt bearbeitet 22.07.2026 19:10:00
GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, a technician can delete arbitrary files from the filesystem as long as the webserver has write rights on them. Upgrade to 10.0...
- EPSS 0.25%
- Veröffentlicht 03.06.2026 14:06:12
- Zuletzt bearbeitet 22.07.2026 19:10:00
GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user with config READ permission can read a specific asset object. Upgrade to 11.0.7 or 10.0.25 to receive a ...
CVE-2026-40108
- EPSS 0.27%
- Veröffentlicht 02.06.2026 23:16:37
- Zuletzt bearbeitet 22.07.2026 19:10:00
GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. This issue has been fixed in version 11.0.7.