Skip to main content

Vendor/product archive

glpi-project / glpi CVEs

Beta · best-effort

189 CVEs tagged to glpi-project / glpi14 Critical, 63 High, 104 Medium, 8 Low, 0 Unrated.

CVE-2023-37278

Published Jul 13, 2023

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An administrator can trigger SQL injec…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36808

Published Jul 5, 2023

GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35940

Published Jul 5, 2023

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35939

Published Jul 5, 2023

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a on a file accessible by an authentic…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35924

Published Jul 5, 2023

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory endpoint can be used to drive a SQL injection attac…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34244

Published Jul 5, 2023

GLPI is a free asset and IT management software package. Starting in version 9.4.0 and prior to version 10.0.8, a malicious link can be crafted by an unauthenticated user that can…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34107

Published Jul 5, 2023

GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights check on a on a file accessible…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34106

Published Jul 5, 2023

GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an incorrect rights check on a on a file accessible b…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28852

Published Apr 5, 2023

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 9.5.13 and 10.0.7, a user with dashboard administration rights may hack th…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28849

Published Apr 5, 2023

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.7, GLPI inventory endpoint can be used to drive a SQL injection attac…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-28838

Published Apr 5, 2023

GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 9.5.13 and 10.0.7, a SQL Injection vulnerability allow users with access ri…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-28639

Published Apr 5, 2023

GLPI is a free asset and IT management software package. Starting in version 0.85 and prior to versions 9.5.13 and 10.0.7, a malicious link can be crafted by an unauthenticated us…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28636

Published Apr 5, 2023

GLPI is a free asset and IT management software package. Starting in version 0.60 and prior to versions 9.5.13 and 10.0.7, a vulnerability allows an administrator to create a mali…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28634

Published Apr 5, 2023

GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, a user who has the Technician profile could see and gene…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28633

Published Apr 5, 2023

GLPI is a free asset and IT management software package. Starting in version 0.84 and prior to versions 9.5.13 and 10.0.7, usage of RSS feeds is subject to server-side request for…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-28632

Published Apr 5, 2023

GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, an authenticated user can modify emails of any user, and…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23610

Published Jan 26, 2023

GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standar…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22725

Published Jan 26, 2023

GLPI is a Free Asset and IT Management Software package. Versions 0.6.0 and above, prior to 10.0.6 are vulnerable to Cross-site Scripting. This vulnerability allow for an administ…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22724

Published Jan 26, 2023

GLPI is a Free Asset and IT Management Software package. Versions prior to 10.0.6 are subject to Cross-site Scripting via malicious RSS feeds. An Administrator can import a malici…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22722

Published Jan 26, 2023

GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 are subject to Cross-site Scripting. An attacker can persuade a victim into open…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22500

Published Jan 26, 2023

GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6 are vulnerable to Incorrect Authorization. This vulnerability allow unauthorize…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41941

Published Jan 26, 2023

GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6, are subject to Cross-site Scripting. An administrator may store malicious code…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39376

Published Nov 3, 2022

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and so…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-39375

Published Nov 3, 2022

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and so…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39373

Published Nov 3, 2022

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and so…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 189 CVEsPage 4 of 8