Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

GLPI — Vulnerabilities & Security Advisories 177

All 177 CVE vulnerabilities found in GLPI, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with GLPI, the open-source information technology asset management system. It collects various weakness types, including remote code execution, cross-site scripting, and authentication bypasses, covering the full historical range of known issues. Here you can track the vendor’s security advisories, understand specific weakness classes, and review the product’s complete vulnerability history.

Vendor: INDEPNET Development Team

CVE ID Title CVSS Severity Published
CVE-2026-53629 GLPI: SQL injection in history tab CWE-89 7.1 High 2026-09-25
CVE-2026-53626 GLPI: Arbitrary Document Read via Form Context Authorization Bypass CWE-639 7.1 High 2026-09-25
CVE-2026-48482 GLPI: RCE via Form import CWE-22 9.4 Critical 2026-09-25
CVE-2026-53625 GLPI: Privilege Escalation via authtype API manipulation CWE-862 7.5 High 2026-09-25
CVE-2026-53610 GLPI: Reflected XSS in dashboards CWE-79 7.5 High 2026-09-25
CVE-2026-47679 GLPI: arbitrary file deletion CWE-22 8.5 High 2026-09-25
CVE-2026-55214 GLPI: Stored XSS in suppliers CWE-116 8.5 High 2026-09-25
CVE-2026-49470 GLPI: Missing Rate Limiting on Login and TOTP Verification — Account Takeover via Brute Force CWE-307 7.7 High 2026-09-25
CVE-2026-55217 GLPI: Unallowed modfication of knowbase items comments and translations CWE-285 5.3 Medium 2026-09-25
CVE-2026-53628 GLPI: Unallowed authentication method update by administrator CWE-285 5.9 Medium 2026-09-25
CVE-2026-45801 GLPI: Unauthorized Debug Mode Activation via Profile Update (Privilege Escalation) CWE-269 5.3 Medium 2026-09-25
CVE-2026-53627 GLPI: Unexpected access to update operations through the API CWE-862 6.0 Medium 2026-09-25
CVE-2026-49469 GLPI: LDAP filter injection in user import feature CWE-90 4.6 Medium 2026-09-25
CVE-2026-13490 glpi-project glpi Document document.send.php canViewFile authorization CWE-639 3.7 Low 2026-06-28
CVE-2026-42321 GLPI has stored XSS in asset locks CWE-79 - - 2026-06-03
CVE-2026-42320 GLPI vulnerable to arbitrary file access CWE-862 - - 2026-06-03
CVE-2026-42318 GLPI Vulnerable to Arbitrary Item Deletion via Planning Endpoint CWE-862 7.0 High 2026-06-03
CVE-2026-42317 GLPI vulnerable to arbitrary files deletion by technician CWE-862 - - 2026-06-03
CVE-2026-44281 GLPI vulnerable to unauthorized reading of a specific asset object CWE-862 - - 2026-06-03
CVE-2026-40108 GLPI Vulnerable to Stored XSS in ITIL Costs CWE-79 - - 2026-06-02
CVE-2026-5385 GLPI 11.0.0 - Stored XSS in knowledge base CWE-79 - - 2026-06-02
CVE-2026-32312 GLPI: Unauthorized export of form structure CWE-862 - - 2026-05-18
CVE-2026-29047 GLPI has an Authenticated SQL Injection via log exports CWE-89 7.2 High 2026-04-06
CVE-2026-26263 GLPI has an Unauthenticated SQL Injection via Search engine CWE-89 8.1 High 2026-04-06
CVE-2026-26027 GLPI has an Unauthenticated Stored XSS via inventory CWE-79 7.5 High 2026-04-06
CVE-2026-26026 GLPI has a Server-Side Template Injection via Double-Compilation CWE-94 9.1 Critical 2026-04-06
CVE-2026-25932 GLPI has Stored XSS in Supplier 'Website' field CWE-116 7.2 High 2026-04-06
CVE-2026-25937 GLPI has a MFA bypass CWE-287 6.5 Medium 2026-03-17
CVE-2026-25936 GLPI Vulnerable to Authenticated SQL Injection CWE-89 6.5 Medium 2026-03-17
CVE-2026-22248 GLPI affected by Remote Code Execution via malicious upload CWE-502 8.1 High 2026-03-11

All 177 known CVE vulnerabilities affecting GLPI with full Chinese analysis, references, and POCs where available.