| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-28632 | GLPI vulnerable to account takeover by authenticated user | glpi-project | glpi | High | 8.1 | 2023-04-05 14:45:12 | Deep Dive |
| CVE-2023-28639 | GLPI vulnerable to reflected Cross-site Scripting in search pages | glpi | glpi | Medium | 6.1 | 2023-04-05 00:00:00 | Deep Dive |
| CVE-2022-41941 | glpi contains XSS Stored inside Standard Interface Help Link href attribute | glpi-project | glpi | Medium | 6.2 | 2023-01-25 06:06:23 | Deep Dive |
| CVE-2023-22500 | glpi Unauthorized access to inventory files | glpi-project | glpi | High | 7.5 | 2023-01-25 06:03:57 | Deep Dive |
| CVE-2023-22722 | glpi subject to Cross-site Scripting (XSS) - Reflected | glpi-project | glpi | Medium | 6.8 | 2023-01-25 05:58:01 | Deep Dive |
| CVE-2023-22724 | glpi contains XSS in RSS Description Link | glpi-project | glpi | Medium | 6.2 | 2023-01-25 05:55:10 | Deep Dive |
| CVE-2023-22725 | glpi vulnerable to XSS on external links | glpi-project | glpi | Medium | 6.2 | 2023-01-25 05:50:19 | Deep Dive |
| CVE-2023-23610 | glpi vulnerable to Unauthorized access to data export | glpi-project | glpi | Medium | 6.5 | 2023-01-25 05:46:36 | Deep Dive |
| CVE-2022-39181 | GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS) | GLPI | Reports plugin for GLPI | Medium | 6.1 | 2022-11-17 22:27:55 | Deep Dive |
| CVE-2022-39234 | user session persists even after permanently deleting account in GLPI | glpi-project | glpi | Medium | 4.7 | 2022-11-03 00:00:00 | Deep Dive |
| CVE-2022-39262 | Stored Cross-Site Scripting (XSS) on login page in GLPI | glpi-project | glpi | Medium | 5.2 | 2022-11-03 00:00:00 | Deep Dive |
| CVE-2022-39276 | Blind Server-Side Request Forgery (SSRF) in RSS feeds and planning | glpi-project | glpi | Low | 3.5 | 2022-11-03 00:00:00 | Deep Dive |
| CVE-2022-39277 | Cross-Site Scripting (XSS) in external links in GLPI | glpi-project | glpi | Medium | 4.5 | 2022-11-03 00:00:00 | Deep Dive |
| CVE-2022-39323 | SQL Injection on REST API in GLPI | glpi-project | glpi | High | 7.4 | 2022-11-03 00:00:00 | Deep Dive |
| CVE-2022-39370 | Improper access to debug panel in GLPI | glpi-project | glpi | Medium | 4.3 | 2022-11-03 00:00:00 | Deep Dive |
| CVE-2022-39371 | Stored Cross-Site Scripting (XSS) through asset inventory in GLPI | glpi-project | glpi | High | 7.5 | 2022-11-03 00:00:00 | Deep Dive |
| CVE-2022-39372 | Stored Cross-Site Scripting (XSS) in user information in GLPI | glpi-project | glpi | Low | 3.5 | 2022-11-03 00:00:00 | Deep Dive |
| CVE-2022-39373 | Stored Cross-Site Scripting (XSS) in entity name in GLPI | glpi-project | glpi | Medium | 4.9 | 2022-11-03 00:00:00 | Deep Dive |
| CVE-2022-39375 | Cross-Site Scripting (XSS) through public RSS feed in GLPI | glpi-project | glpi | Medium | 4.5 | 2022-11-03 00:00:00 | Deep Dive |
| CVE-2022-39376 | Improper input validation on emails links in GLPI | glpi-project | glpi | Low | 2.6 | 2022-11-03 00:00:00 | Deep Dive |