Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

glpi — Vulnerabilities & Security Advisories 164

All 164 CVE vulnerabilities found in glpi, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with GLPI, an open-source IT asset and helpdesk management solution, categorized under general software weakness types. The collection aggregates detailed records of discovered flaws, configuration errors, and exploitation vectors that have been reported or disclosed within the system over a defined historical period. By consulting this resource, security professionals and IT administrators can effectively track vendor security advisories to stay informed about critical updates and patches. Users can also gain a deeper understanding of specific weakness classes affecting enterprise management tools, analyzing patterns in how these vulnerabilities manifest in real-world deployment scenarios. Furthermore, the page serves as a comprehensive lookup for a product’s vulnerability history, allowing teams to assess the cumulative security posture of GLPI installations and prioritize remediation efforts based on severity and relevance. This structured approach facilitates proactive risk management and helps organizations maintain compliance with security standards by identifying known issues before they are exploited. The data provided supports informed decision-making regarding software procurement, patch management schedules, and infrastructure hardening strategies, ensuring that stakeholders have access to accurate and actionable intelligence regarding the safety and integrity of their GLPI environments.

Vendor: INDEPNET Development Team

CVE IDTitleCVSSSeverityPublished
CVE-2023-35924 GLPI vulnerable to SQL injection via inventory agent request CWE-89 8.6 High2023-07-05
CVE-2023-34244 GLPI vulnerable to reflected XSS in search pages CWE-79 6.5 Medium2023-07-05
CVE-2023-34107 GLPI vulnerable to unauthorized access to KnowbaseItem data CWE-284 6.5 Medium2023-07-05
CVE-2023-34106 GLPI vulnerable to unauthorized access to User data CWE-284 6.5 Medium2023-07-05
CVE-2023-28852 GLPI vulnerable to stored Cross-site Scripting through dashboard administration CWE-79 4.8 Medium2023-04-05
CVE-2023-28849 GLPI vulnerable to SQL injection and Stored XSS via inventory agent request CWE-89 10.0 Critical2023-04-05
CVE-2023-28838 GLPI vulnerable to SQL injection through dynamic reports CWE-89 9.6 Critical2023-04-05
CVE-2023-28636 GLPI vulnerable to stored Cross-site Scripting in external links CWE-79 4.5 Medium2023-04-05
CVE-2023-28634 GLPI vulnerable to Privilege Escalation from Technician to Super-Admin CWE-285 8.8 High2023-04-05
CVE-2023-28633 GLPI vulnerable to Blind Server-Side Request Forgery (SSRF) in RSS feeds CWE-918 3.5 Low2023-04-05
CVE-2023-28632 GLPI vulnerable to account takeover by authenticated user CWE-269 8.1 High2023-04-05
CVE-2023-28639 GLPI vulnerable to reflected Cross-site Scripting in search pages CWE-79 6.1 Medium2023-04-05
CVE-2022-41941 glpi contains XSS Stored inside Standard Interface Help Link href attribute CWE-79 6.2 Medium2023-01-25
CVE-2023-22500 glpi Unauthorized access to inventory files CWE-863 7.5 High2023-01-25
CVE-2023-22722 glpi subject to Cross-site Scripting (XSS) - Reflected CWE-79 6.8 Medium2023-01-25
CVE-2023-22724 glpi contains XSS in RSS Description Link CWE-79 6.2 Medium2023-01-25
CVE-2023-22725 glpi vulnerable to XSS on external links CWE-79 6.2 Medium2023-01-25
CVE-2023-23610 glpi vulnerable to Unauthorized access to data export CWE-269 6.5 Medium2023-01-25
CVE-2022-39234 user session persists even after permanently deleting account in GLPI CWE-613 4.7 Medium2022-11-03
CVE-2022-39262 Stored Cross-Site Scripting (XSS) on login page in GLPI CWE-83 5.2 Medium2022-11-03
CVE-2022-39276 Blind Server-Side Request Forgery (SSRF) in RSS feeds and planning CWE-918 3.5 Low2022-11-03
CVE-2022-39277 Cross-Site Scripting (XSS) in external links in GLPI CWE-79 4.5 Medium2022-11-03
CVE-2022-39323 SQL Injection on REST API in GLPI CWE-89 7.4 High2022-11-03
CVE-2022-39370 Improper access to debug panel in GLPI CWE-284 4.3 Medium2022-11-03
CVE-2022-39371 Stored Cross-Site Scripting (XSS) through asset inventory in GLPI CWE-80 7.5 High2022-11-03
CVE-2022-39372 Stored Cross-Site Scripting (XSS) in user information in GLPI CWE-79 3.5 Low2022-11-03
CVE-2022-39373 Stored Cross-Site Scripting (XSS) in entity name in GLPI CWE-79 4.9 Medium2022-11-03
CVE-2022-39375 Cross-Site Scripting (XSS) through public RSS feed in GLPI CWE-79 4.5 Medium2022-11-03
CVE-2022-39376 Improper input validation on emails links in GLPI CWE-20 2.6 Low2022-11-03
CVE-2022-31187 Stored Cross Site Scripting (XSS) through global search in GLPI CWE-79 6.8 Medium2022-09-14

All 164 known CVE vulnerabilities affecting glpi with full Chinese analysis, references, and POCs where available.