All 7 CVE vulnerabilities found in glpi-inventory-plugin, with AI-generated Chinese analysis, references, and POCs.
Vendor: glpi-project
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-26001 | GLPI Inventory Plugin has SQL Injection on dropdown_calendar Report CWE-89 | 7.1 | High | 2026-03-17 |
| CVE-2026-25590 | GLPI Inventory Plugin has Reflected XSS in task jobs CWE-79 | 4.5 | Medium | 2026-03-03 |
| CVE-2025-32786 | GLPI Inventory Plugin is Vulnerable to Unauthenticated SQL Injection CWE-89 | 7.5 | High | 2025-11-04 |
| CVE-2025-27147 | GLPI Inventory plugin has Improper Access Control Vulnerability CWE-22 | 8.2 | High | 2025-03-25 |
| CVE-2025-26626 | GLPI Inventory Plugin vulnerable to reflective Cross-site Scripting CWE-79 | 6.5 | Medium | 2025-03-14 |
| CVE-2022-31082 | SQL Injection via package deployment tasks in glpi-inventory-plugin CWE-89 | 5.8 | Medium | 2022-06-27 |
| CVE-2022-31062 | Unauthenticated Local File Inclusion CWE-22 | 5.3 | Medium | 2022-06-20 |
All 7 known CVE vulnerabilities affecting glpi-inventory-plugin with full Chinese analysis, references, and POCs where available.