| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-22044 | GLPI is Vulnerable to Authenticated SQL Injection | glpi-project | glpi | Medium | 6.5 | 2026-02-04 17:15:39 | Deep Dive |
| CVE-2026-23624 | GLPI is vulnerable to session stealing on externally authenticated user change | glpi-project | glpi | Medium | 4.3 | 2026-02-04 17:15:34 | Deep Dive |
| CVE-2026-22247 | GLPI is Vulnerable to SSRF via Webhooks | glpi-project | glpi | Medium | 4.1 | 2026-02-04 17:10:30 | Deep Dive |
| CVE-2025-66417 📌 | GLPI has an unauthenticated SQL injection through the inventory endpoint | glpi-project | glpi | High | 7.5 | 2026-01-15 16:25:03 | Deep Dive |
| CVE-2025-64516 🧪 | GLPI incorrectly authorizes access to documents | glpi-project | glpi | High | 7.5 | 2026-01-15 16:01:03 | Deep Dive |
| CVE-2023-53943 | GLPI 9.5.7 Username Enumeration Vulnerability via Lost Password Endpoint | Glpi-Project | GLPI | Medium | 5.3 | 2025-12-18 19:53:36 | Deep Dive |
| CVE-2025-64520 | GLPI vulnerable to unauthorized access to restricted Knowledge Base items through the API | glpi-project | glpi | Medium | 6.5 | 2025-12-16 21:59:03 | Deep Dive |
| CVE-2025-59935 | GLPI Vulnerable to Unauthenticated Stored XSS on the Inventory page | glpi-project | glpi | Medium | 6.5 | 2025-12-16 16:34:46 | Deep Dive |
| CVE-2025-32786 🧪 | GLPI Inventory Plugin is Vulnerable to Unauthenticated SQL Injection | glpi-project | glpi-inventory-plugin | High | 7.5 | 2025-11-04 20:18:44 | Deep Dive |
| CVE-2025-53105 🧪 | GLPI permits unauthorized rules execution order | glpi-project | glpi | High | 7.5 | 2025-08-27 14:40:36 | Deep Dive |
| CVE-2025-54780 🧪 | glpi-screenshot-plugin exposes local files in /ajax/screenshot.php | cconard96 | glpi-screenshot-plugin | High | 7.7 | 2025-08-05 00:08:38 | Deep Dive |
| CVE-2025-53357 | GLPI permits reservation modification by unauthorized users | glpi-project | glpi | Medium | 5.4 | 2025-07-30 14:17:59 | Deep Dive |
| CVE-2025-53113 | GLPI technicians can access unauthorized information through external links | glpi-project | glpi | Low | 2.7 | 2025-07-30 14:16:37 | Deep Dive |
| CVE-2025-53112 | GLPI's incomprehensive permission checks can lead to data removal from allowed users | glpi-project | glpi | Medium | 4.3 | 2025-07-30 14:15:22 | Deep Dive |
| CVE-2025-53111 | GLPI exposes data to non-allowed users | glpi-project | glpi | Medium | 6.5 | 2025-07-30 14:14:26 | Deep Dive |
| CVE-2025-53008 | GLPI's MailCollector Receiver is vulnerable to credential exfiltration | glpi-project | glpi | Medium | 6.5 | 2025-07-30 14:09:59 | Deep Dive |
| CVE-2025-52897 | GLPI is vulnerable to XSS and open redirection attacks through planning feature | glpi-project | glpi | Medium | 6.5 | 2025-07-30 14:07:59 | Deep Dive |
| CVE-2025-52567 | GLPI has overly permissive URL verification | glpi-project | glpi | Low | 3.5 | 2025-07-30 14:07:15 | Deep Dive |
| CVE-2025-27514 | GLPI is susceptible to Stored XSS attack through project's kanban | glpi-project | glpi | Medium | 4.5 | 2025-07-29 17:39:29 | Deep Dive |
| CVE-2025-27147 🧪 | GLPI Inventory plugin has Improper Access Control Vulnerability | glpi-project | glpi-inventory-plugin | High | 8.2 | 2025-03-25 14:26:45 | Deep Dive |