Skip to main content

Vendor archive

glpi-project CVEs

Beta · best-effort

205 CVEs tagged to vendor glpi-project16 Critical, 70 High, 111 Medium, 8 Low, 0 Unrated.

CVE-2022-31187

Published Sep 14, 2022

GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and sof…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31143

Published Sep 14, 2022

GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and sof…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31068

Published Jun 28, 2022

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all GLPI instance…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31061

Published Jun 28, 2022

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-31056

Published Jun 28, 2022

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance fo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-31082

Published Jun 27, 2022

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. glpi-inventory-plugin is a plugin for…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31062

Published Jun 20, 2022

### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if de…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29250

Published Jun 9, 2022

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to version 10.0.1 it…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24876

Published Jun 9, 2022

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Kanban is a GLPI view to display Projec…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24869

Published Apr 21, 2022

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can use…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24868

Published Apr 21, 2022

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can exp…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24867

Published Apr 21, 2022

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you pass the config to the javascr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44617

Published Mar 28, 2022

A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-21720

Published Jan 28, 2022

GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving normally inaccessible data via SQL injection. Ver…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21719

Published Jan 28, 2022

GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cross-site scripting. Version 9.5.7 contains a patch for this…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43778

Published Nov 24, 2021

Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-39213

Published Sep 15, 2021

GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom hea…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39211

Published Sep 15, 2021

GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI and server information. This iss…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39210

Published Sep 15, 2021

GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39209

Published Sep 15, 2021

GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cross-Site Request Forgery (CSRF) protection in man…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3486

Published May 26, 2021

GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-30144

Published Apr 6, 2021

The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21327

Published Mar 8, 2021

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 non…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21326

Published Mar 8, 2021

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 it…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21325

Published Mar 8, 2021

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 a n…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 126-150 of 205 CVEsPage 6 of 9