Vulnerability index

Browse CVEs

170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Barcode HIGH 7.5
CVE-2021-43778EPSS 53%

Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are …

Fix: 2.6.1+
Fix from $1,950 2021-11-24
Glpi HIGH 8.8
CVE-2021-39213

GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable…

Fix: 9.5.6+
Fix from $1,950 2021-09-15
Glpi MEDIUM 6.5
CVE-2021-39210

GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses …

Fix: 9.5.6+
Fix from $1,600 2021-09-15
Glpi MEDIUM 5.3
CVE-2021-39211

GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI an…

Fix: 9.5.6+
Fix from $1,600 2021-09-15
Glpi HIGH 8.8
CVE-2021-39209

GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cross-Site Request Fo…

Fix: 9.5.6+
Fix from $1,950 2021-09-15
Glpi MEDIUM 6.1
CVE-2021-3486

GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.

No fix yet
Fix from $1,600 2021-05-26
Glpi HIGH 7.5
CVE-2021-21327

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…

Fix: 9.5.4+
Fix from $1,950 2021-03-08
Glpi MEDIUM 6.5
CVE-2021-21326

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…

Fix: 9.5.4+
Fix from $1,600 2021-03-08
Glpi MEDIUM 6.5
CVE-2021-21324

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…

Fix: 9.5.4+
Fix from $1,600 2021-03-08
Glpi MEDIUM 6.1
CVE-2021-21313

GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In G…

Fix: 9.5.4+
Fix from $1,600 2021-03-03
Glpi MEDIUM 5.7
CVE-2021-21255

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…

Patch available
Fix from $1,600 2021-03-02
Glpi MEDIUM 5.4
CVE-2021-21258

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…

Fix: 9.5.4+
Fix from $1,600 2021-03-02
Glpi MEDIUM 6.5
CVE-2020-26212

GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk fe…

Fix: 9.5.3+
Fix from $1,600 2020-11-25
Glpi CRITICAL 9.1
CVE-2020-15175EPSS 71%

In GLPI before version 9.5.2, the `​pluginimage.send.php​` endpoint allows a user to specify an image from a plugin. The parameters can be maliciousl…

Fix: 9.5.2+
Fix from $2,300 2020-10-07
Glpi HIGH 8.6
CVE-2020-15176

In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing…

Fix: 9.5.2+
Fix from $1,950 2020-10-07
Glpi MEDIUM 6.1
CVE-2020-15177

In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_base` and `url_base_api`. The…

Fix: 9.5.2+
Fix from $1,600 2020-10-07
Glpi MEDIUM 5.3
CVE-2020-15217

In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in…

Fix: 9.5.2+
Fix from $1,600 2020-10-07
Glpi HIGH 7.5
CVE-2020-11031

In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user se…

Fix: 9.5.0+
Fix from $1,950 2020-09-23
Glpi HIGH 7.1
CVE-2020-15108

In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1.

Fix: 9.5.1+
Fix from $1,950 2020-07-17
Glpi HIGH 8.8
CVE-2020-11060EPSS 11%

In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited…

Fix: 9.4.6+
Fix from $1,950 2020-05-12
Glpi MEDIUM 5.4
CVE-2020-11062

In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has been fixed in vers…

Fix: 9.4.6+
Fix from $1,600 2020-05-12
Glpi MEDIUM 5.3
CVE-2020-5248

GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means …

Fix: 9.4.6+
Fix from $1,600 2020-05-12
Glpi MEDIUM 6.1
CVE-2020-11034EPSS 8%

In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is f…

Fix: 9.4.6+
Fix from $1,600 2020-05-05
Glpi MEDIUM 5.4
CVE-2020-11036

In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored XSS in the comments of items …

Fix: 9.4.6+
Fix from $1,600 2020-05-05
Glpi HIGH 7.2
CVE-2020-11032

In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician …

Mitigation only
Fix from $1,950 2020-05-05
Glpi HIGH 8.8
CVE-2019-14666

GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads t…

Fix: after 9.4.3
Fix from $1,950 2019-09-25
Glpi MEDIUM 5.4
CVE-2019-1010307

GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege esc…

No fix yet
Fix from $1,600 2019-07-15
Glpi MEDIUM 5.9
CVE-2019-13240

An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during…

Fix: 9.4.1+
Fix from $1,600 2019-07-10
Glpi MEDIUM 6.1
CVE-2019-13239

inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.

Fix: 9.4.3+
Fix from $1,600 2019-07-04
Glpi HIGH 8.1
CVE-2019-10233

Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.

Fix: 9.4.1.1+
Fix from $1,950 2019-03-27