Glpi-project
Glpi-project Glpi: vulnerabilidades y CVE
Glpi-project Glpi tiene 191 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 26 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE191
Últimos 12 meses17
Críticas26
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-35914 | Crítica (9.8) | 100% | ⚠ Explotación activa | 19 sept 2022 | /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-55217 | Media (5.3) | 0.31% | — | 25 sept 2026 | GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations without the… |
| CVE-2026-13490 | Media (6.3) | 0.46% | — | 28 jun 2026 | A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.php of the component Document Handler. Such… |
| CVE-2026-44281 | Alta (7) | 0.39% | — | 3 jun 2026 | GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user with config READ permission can read a specific asset object. Upgrade to… |
| CVE-2026-32312 | Media (5.1) | 0.29% | — | 19 may 2026 | GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue has been fixed in… |
| CVE-2026-29047 | Alta (8.8) | 0.45% | — | 6 abr 2026 | GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the logs export feature. This vulnerability is fixed in 10.0.24… |
| CVE-2026-26263 | Crítica (9.8) | 0.40% | — | 6 abr 2026 | GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6. |
| CVE-2026-26027 | Media (6.1) | 0.28% | — | 6 abr 2026 | GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6. |
| CVE-2026-26026 | Alta (7.2) | 0.54% | — | 6 abr 2026 | GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6. |
| CVE-2026-25932 | Media (4.8) | 0.32% | — | 6 abr 2026 | GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24. |
| CVE-2026-23624 | Media (6.5) | 0.40% | — | 4 feb 2026 | GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO variables, a user can steal a GLPI session… |
| CVE-2026-22247 | Crítica (9.1) | 0.34% | — | 4 feb 2026 | GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issue has been patched in version 11.0.5. |
| CVE-2026-22044 | Alta (8.8) | 0.28% | — | 4 feb 2026 | GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This issue has been patched in version 10.0.23. |
| CVE-2025-66417 | Crítica (9.8) | 0.48% | — | 15 ene 2026 | GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3. |
| CVE-2025-64516 | Alta (7.5) | 0.32% | — | 15 ene 2026 | GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this… |
| CVE-2023-53943 | Media (6.9) | 0.35% | — | 18 dic 2025 | GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email addresses by submitting… |
| CVE-2025-64520 | Media (4.3) | 0.22% | — | 16 dic 2025 | GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to… |
| CVE-2025-59935 | Media (6.5) | 0.29% | — | 16 dic 2025 | GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inventory endpoint. Users should upgrade to… |
| CVE-2025-53357 | Media (5.4) | 0.18% | — | 30 jul 2025 | GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 0.78… |
| CVE-2025-53113 | Baja (2.7) | 0.23% | — | 30 jul 2025 | GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 0.65… |
| CVE-2025-53112 | Media (4.3) | 0.20% | — | 30 jul 2025 | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.1.0 through 10.0.18, a lack of permission checks can result in… |
| CVE-2025-53111 | Media (6.5) | 0.26% | — | 30 jul 2025 | GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized access to some resources. This is fixed in version 10.0.19. |
| CVE-2025-53008 | Media (6.5) | 0.26% | — | 30 jul 2025 | GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.3.1 through… |
| CVE-2025-52897 | Media (6.1) | 0.21% | — | 30 jul 2025 | GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to attempt a phishing attack from the planning feature. This is fixed in… |
| CVE-2025-52567 | Media (5) | 0.18% | — | 30 jul 2025 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 0.84 through 10.0.18, usage of RSS feeds or external calendars… |
| CVE-2025-27514 | Media (5.4) | 0.19% | — | 29 jul 2025 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a technician can use a malicious payload to… |
| CVE-2025-24801 | Alta (8.8) | 21% | — | 18 mar 2025 | GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18. |
| CVE-2025-24799 | Crítica (9.8) | 87% | — | 18 mar 2025 | GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18. |
| CVE-2025-21619 | Alta (8.2) | 0.43% | — | 18 mar 2025 | GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This vulnerability is fixed in 10.0.18. |
| CVE-2025-25192 | Media (6.5) | 0.67% | — | 25 feb 2025 | GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive information. Version 10.0.18 contains a patch. As a workaround, one may… |
| CVE-2025-23046 | Media (6.3) | 0.46% | — | 25 feb 2025 | GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.18, if a "Mail servers" authentication provider is configured to use an Oauth connection provided by the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.