Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

GLPI — Vulnerabilities & Security Advisories 163

All 163 CVE vulnerabilities found in GLPI, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumeration vulnerability data specifically for the GLPI product developed by the Teclib' vendor. It focuses on identifying security flaws and misconfigurations associated with this popular open-source IT asset management and service desk software. The collection encompasses a broad spectrum of vulnerability classes, including SQL injection, cross-site scripting, privilege escalation, and information disclosure issues. The time range covered extends from the initial public release of GLPI through to the most recent security advisories, providing a comprehensive historical view of the product's security landscape. This period captures the evolution of security patches and the remediation of critical flaws as the software matured and expanded its feature set. Users browsing this resource can track the vendor's security response patterns and advisory timelines to assess the reliability of their updates. Additionally, the page serves as a reference point for understanding the specific manifestations of common weakness classes within the GLPI ecosystem, helping developers and administrators identify recurring code patterns that lead to exploits. By examining the product's vulnerability history, stakeholders can perform risk assessments, prioritize patching efforts, and benchmark their deployment security against known public incidents. The data is structured to facilitate comparative analysis across different GLPI versions and releases. This aggregation aims to provide clear, actionable insights into the security posture of the software over time. It supports informed decision-making for IT professionals responsible for maintaining the integrity and availability of their GLPI installations in enterprise environments.

Vendor: INDEPNET Development Team

CVE IDTitleCVSSSeverityPublished
CVE-2026-42321 GLPI has stored XSS in asset locks CWE-79--2026-06-03
CVE-2026-42320 GLPI vulnerable to arbitrary file access CWE-862--2026-06-03
CVE-2026-42318 GLPI Vulnerable to Arbitrary Item Deletion via Planning Endpoint CWE-862--2026-06-03
CVE-2026-42317 GLPI vulnerable to arbitrary files deletion by technician CWE-862--2026-06-03
CVE-2026-44281 GLPI vulnerable to unauthorized reading of a specific asset object CWE-862--2026-06-03
CVE-2026-40108 GLPI Vulnerable to Stored XSS in ITIL Costs CWE-79--2026-06-02
CVE-2026-5385 GLPI 11.0.0 - Stored XSS in knowledge base CWE-79--2026-06-02
CVE-2026-32312 GLPI: Unauthorized export of form structure CWE-862--2026-05-18
CVE-2026-29047 GLPI has an Authenticated SQL Injection via log exports CWE-89 7.2 High2026-04-06
CVE-2026-26263 GLPI has an Unauthenticated SQL Injection via Search engine CWE-89 8.1 High2026-04-06
CVE-2026-26027 GLPI has an Unauthenticated Stored XSS via inventory CWE-79 7.5 High2026-04-06
CVE-2026-26026 GLPI has a Server-Side Template Injection via Double-Compilation CWE-94 9.1 Critical2026-04-06
CVE-2026-25932 GLPI has Stored XSS in Supplier 'Website' field CWE-116 7.2 High2026-04-06
CVE-2026-25937 GLPI has a MFA bypass CWE-287 6.5 Medium2026-03-17
CVE-2026-25936 GLPI Vulnerable to Authenticated SQL Injection CWE-89 6.5 Medium2026-03-17
CVE-2026-22248 GLPI affected by Remote Code Execution via malicious upload CWE-502 8.1 High2026-03-11
CVE-2026-22044 GLPI is Vulnerable to Authenticated SQL Injection CWE-89 6.5 Medium2026-02-04
CVE-2026-23624 GLPI is vulnerable to session stealing on externally authenticated user change CWE-384 4.3 Medium2026-02-04
CVE-2026-22247 GLPI is Vulnerable to SSRF via Webhooks CWE-918 4.1 Medium2026-02-04
CVE-2025-66417 GLPI has an unauthenticated SQL injection through the inventory endpoint CWE-89 7.5 High2026-01-15
CVE-2025-64516 GLPI incorrectly authorizes access to documents CWE-284 7.5 High2026-01-15
CVE-2023-53943 GLPI 9.5.7 Username Enumeration Vulnerability via Lost Password Endpoint CWE-203 5.3 Medium2025-12-18
CVE-2025-64520 GLPI vulnerable to unauthorized access to restricted Knowledge Base items through the API CWE-862 6.5 Medium2025-12-16
CVE-2025-59935 GLPI Vulnerable to Unauthenticated Stored XSS on the Inventory page CWE-79 6.5 Medium2025-12-16
CVE-2025-53105 GLPI permits unauthorized rules execution order CWE-269 7.5 High2025-08-27
CVE-2025-53357 GLPI permits reservation modification by unauthorized users CWE-639 5.4 Medium2025-07-30
CVE-2025-53113 GLPI technicians can access unauthorized information through external links CWE-284 2.7 Low2025-07-30
CVE-2025-53112 GLPI's incomprehensive permission checks can lead to data removal from allowed users CWE-284 4.3 Medium2025-07-30
CVE-2025-53111 GLPI exposes data to non-allowed users CWE-284 6.5 Medium2025-07-30
CVE-2025-53008 GLPI's MailCollector Receiver is vulnerable to credential exfiltration CWE-522 6.5 Medium2025-07-30

All 163 known CVE vulnerabilities affecting GLPI with full Chinese analysis, references, and POCs where available.