Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

glpi — Vulnerabilities & Security Advisories 164

All 164 CVE vulnerabilities found in glpi, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with GLPI, an open-source IT asset and helpdesk management solution, categorized under general software weakness types. The collection aggregates detailed records of discovered flaws, configuration errors, and exploitation vectors that have been reported or disclosed within the system over a defined historical period. By consulting this resource, security professionals and IT administrators can effectively track vendor security advisories to stay informed about critical updates and patches. Users can also gain a deeper understanding of specific weakness classes affecting enterprise management tools, analyzing patterns in how these vulnerabilities manifest in real-world deployment scenarios. Furthermore, the page serves as a comprehensive lookup for a product’s vulnerability history, allowing teams to assess the cumulative security posture of GLPI installations and prioritize remediation efforts based on severity and relevance. This structured approach facilitates proactive risk management and helps organizations maintain compliance with security standards by identifying known issues before they are exploited. The data provided supports informed decision-making regarding software procurement, patch management schedules, and infrastructure hardening strategies, ensuring that stakeholders have access to accurate and actionable intelligence regarding the safety and integrity of their GLPI environments.

Vendor: INDEPNET Development Team

CVE IDTitleCVSSSeverityPublished
CVE-2026-13490 glpi-project glpi Document document.send.php canViewFile authorization CWE-639 3.7 Low2026-06-28
CVE-2026-42321 GLPI has stored XSS in asset locks CWE-79--2026-06-03
CVE-2026-42320 GLPI vulnerable to arbitrary file access CWE-862--2026-06-03
CVE-2026-42318 GLPI Vulnerable to Arbitrary Item Deletion via Planning Endpoint CWE-862--2026-06-03
CVE-2026-42317 GLPI vulnerable to arbitrary files deletion by technician CWE-862--2026-06-03
CVE-2026-44281 GLPI vulnerable to unauthorized reading of a specific asset object CWE-862--2026-06-03
CVE-2026-40108 GLPI Vulnerable to Stored XSS in ITIL Costs CWE-79--2026-06-02
CVE-2026-5385 GLPI 11.0.0 - Stored XSS in knowledge base CWE-79--2026-06-02
CVE-2026-32312 GLPI: Unauthorized export of form structure CWE-862--2026-05-18
CVE-2026-29047 GLPI has an Authenticated SQL Injection via log exports CWE-89 7.2 High2026-04-06
CVE-2026-26263 GLPI has an Unauthenticated SQL Injection via Search engine CWE-89 8.1 High2026-04-06
CVE-2026-26027 GLPI has an Unauthenticated Stored XSS via inventory CWE-79 7.5 High2026-04-06
CVE-2026-26026 GLPI has a Server-Side Template Injection via Double-Compilation CWE-94 9.1 Critical2026-04-06
CVE-2026-25932 GLPI has Stored XSS in Supplier 'Website' field CWE-116 7.2 High2026-04-06
CVE-2026-25937 GLPI has a MFA bypass CWE-287 6.5 Medium2026-03-17
CVE-2026-25936 GLPI Vulnerable to Authenticated SQL Injection CWE-89 6.5 Medium2026-03-17
CVE-2026-22248 GLPI affected by Remote Code Execution via malicious upload CWE-502 8.1 High2026-03-11
CVE-2026-22044 GLPI is Vulnerable to Authenticated SQL Injection CWE-89 6.5 Medium2026-02-04
CVE-2026-23624 GLPI is vulnerable to session stealing on externally authenticated user change CWE-384 4.3 Medium2026-02-04
CVE-2026-22247 GLPI is Vulnerable to SSRF via Webhooks CWE-918 4.1 Medium2026-02-04
CVE-2025-66417 GLPI has an unauthenticated SQL injection through the inventory endpoint CWE-89 7.5 High2026-01-15
CVE-2025-64516 GLPI incorrectly authorizes access to documents CWE-284 7.5 High2026-01-15
CVE-2023-53943 GLPI 9.5.7 Username Enumeration Vulnerability via Lost Password Endpoint CWE-203 5.3 Medium2025-12-18
CVE-2025-64520 GLPI vulnerable to unauthorized access to restricted Knowledge Base items through the API CWE-862 6.5 Medium2025-12-16
CVE-2025-59935 GLPI Vulnerable to Unauthenticated Stored XSS on the Inventory page CWE-79 6.5 Medium2025-12-16
CVE-2025-53105 GLPI permits unauthorized rules execution order CWE-269 7.5 High2025-08-27
CVE-2025-53357 GLPI permits reservation modification by unauthorized users CWE-639 5.4 Medium2025-07-30
CVE-2025-53113 GLPI technicians can access unauthorized information through external links CWE-284 2.7 Low2025-07-30
CVE-2025-53112 GLPI's incomprehensive permission checks can lead to data removal from allowed users CWE-284 4.3 Medium2025-07-30
CVE-2025-53111 GLPI exposes data to non-allowed users CWE-284 6.5 Medium2025-07-30

All 164 known CVE vulnerabilities affecting glpi with full Chinese analysis, references, and POCs where available.