| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2021-21314 | XSS injection on ticket update | glpi-project | glpi | Medium | 5.4 | 2021-03-03 19:30:15 | Deep Dive |
| CVE-2021-21312 | Stored XSS on documents | glpi-project | glpi | Medium | 5.4 | 2021-03-03 19:25:20 | Deep Dive |
| CVE-2021-21313 | XSS on tabs | glpi-project | glpi | Medium | 4.9 | 2021-03-03 19:25:13 | Deep Dive |
| CVE-2021-21258 | XSS injection in ajax/kanban | glpi-project | glpi | Medium | 6.8 | 2021-03-02 19:45:17 | Deep Dive |
| CVE-2021-21255 | entities switch IDOR | glpi-project | glpi | Medium | 5.8 | 2021-03-02 19:40:20 | Deep Dive |
| CVE-2020-26212 | Any GLPI CalDAV calendars is read-only for every authenticated user | glpi-project | glpi | High | 7.7 | 2020-11-25 17:05:17 | Deep Dive |
| CVE-2020-15226 | SQL Injection in GLPI Search API | glpi-project | glpi | Medium | 5.0 | 2020-10-07 19:20:14 | Deep Dive |
| CVE-2020-15217 | User data exposure in GLPI | glpi-project | glpi | Medium | 5.3 | 2020-10-07 19:10:13 | Deep Dive |
| CVE-2020-15177 | Unauthenticated Stored XSS in GLPI | glpi-project | glpi | High | 8.0 | 2020-10-07 19:05:14 | Deep Dive |
| CVE-2020-15176 | SQL injection in GLPI | glpi-project | glpi | High | 8.7 | 2020-10-07 18:55:12 | Deep Dive |
| CVE-2020-15175 | Unauthenticated File Deletion in GLPI | glpi-project | glpi | High | 7.4 | 2020-10-07 18:45:14 | Deep Dive |
| CVE-2020-11031 | Insecure encryption algorithm in GLPI | glpi-project | GLPI | High | 7.8 | 2020-09-23 15:20:13 | Deep Dive |
| CVE-2020-15108 | SQL Injection in glpi | glpi-project | glpi | High | 7.1 | 2020-07-17 20:30:17 | Deep Dive |
| CVE-2020-11060 | Remote Code Execution in GLPI | glpi-project | GLPI | High | 7.4 | 2020-05-12 19:30:14 | Deep Dive |
| CVE-2020-5248 | Public GLPIKEY can be used to decrypt any data in GLPI | glpi-project | glpi | High | 7.2 | 2020-05-12 16:05:17 | Deep Dive |
| CVE-2020-11036 | XSS in GLPI | glpi-project | GLPI | High | 7.6 | 2020-05-05 21:35:12 | Deep Dive |
| CVE-2020-11035 | weak CSRF tokens in GLPI | glpi-project | GLPI | High | 7.5 | 2020-05-05 21:30:12 | Deep Dive |
| CVE-2020-11034 | bypass of manageRedirect in GLPI | glpi-project | GLPI | Medium | 6.1 | 2020-05-05 21:20:12 | Deep Dive |
| CVE-2020-11033 | Able to read any token through API user endpoint in GLPI | glpi-project | GLPI | Medium | 6.6 | 2020-05-05 21:15:12 | Deep Dive |
| CVE-2020-11032 | SQL injection on addme_observer and addme_assign in GLPI | glpi-project | GLPI | High | 7.6 | 2020-05-05 21:05:12 | Deep Dive |