Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Glpi MEDIUM 5.3
CVE-2023-53943

GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. A…

No fix yet
Fix from $1,600 2025-12-18
Reports MEDIUM 6.1
CVE-2022-39181

GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS). Type 1: Reflected XSS (or Non-Persistent) - The server reads data directly from…

Mitigation only
Fix from $1,600 2022-11-17
Glpi MEDIUM 6.5
CVE-2022-29250

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versio…

Mitigation only
Fix from $1,600 2022-06-09
Glpi CRITICAL 9.8
CVE-2021-44617

A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.

No fix yet
Fix from $2,300 2022-03-28
Glpi MEDIUM 6.1
CVE-2021-3486

GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.

No fix yet
Fix from $1,600 2021-05-26
Glpi HIGH 7.2
CVE-2020-11032

In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician …

Mitigation only
Fix from $1,950 2020-05-05
Glpi MEDIUM 5.4
CVE-2019-1010307

GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege esc…

No fix yet
Fix from $1,600 2019-07-15
Glpi HIGH 8.0
CVE-2016-7507

Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creat…

Mitigation only
Fix from $1,950 2017-07-19
Glpi MEDIUM 5.4
CVE-2016-7509

Cross-site scripting (XSS) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to inject arbitrary web script or HTML by attaching a c…

Mitigation only
Fix from $1,600 2017-07-19
Glpi HIGH 7.5
CVE-2016-7508

Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a certain cha…

No fix yet
Fix from $1,950 2017-06-21
Glpi MEDIUM 6.5
CVE-2012-1037

PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remote authenticated users to execute arbitrary PHP co…

Mitigation only
Fix from $1,600 2012-07-12