Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-26263EPSS 9%
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GL…
Glpi
11.0.6+
HIGH 8.8
CVE-2026-29047
GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection …
Glpi
10.0.24 / 11.0.6+
HIGH 7.2
CVE-2026-26026EPSS 11%
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulne…
Glpi
11.0.6+
MEDIUM 6.1
CVE-2026-26027
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the i…
Glpi
11.0.6+
HIGH 8.8
CVE-2026-26001
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, non sanitiz…
Glpi Inventory
1.6.6+
MEDIUM 6.1
CVE-2026-25590
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, there is a …
Glpi Inventory
1.6.6+
MEDIUM 6.5
CVE-2026-22821
mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vulnerability is fixed in 1.9.4.
More Reporting
1.9.4+
CRITICAL 9.1
CVE-2026-22247
GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through …
Glpi
11.0.5+
HIGH 8.8
CVE-2026-22044
GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This…
Glpi
10.0.23+
MEDIUM 6.5
CVE-2026-23624
GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authenticati…
Glpi
10.0.23 / 11.0.5+
CRITICAL 9.8
CVE-2025-66417
GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inven…
Glpi
11.0.3+
HIGH 7.5
CVE-2025-64516
GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any …
Glpi
10.0.21 / 11.0.3+
MEDIUM 5.3
CVE-2023-53943
GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. A…
Glpi
No fix yet
MEDIUM 6.5
CVE-2025-59935
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store a…
Glpi
10.0.21+
MEDIUM 5.4
CVE-2025-53357
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk f…
Glpi
10.0.19+
MEDIUM 6.5
CVE-2025-53111
GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized acc…
Glpi
10.0.19+
MEDIUM 6.5
CVE-2025-53008
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…
Glpi
10.0.19+
MEDIUM 6.1
CVE-2025-52897
GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to atte…
Glpi
10.0.19+
MEDIUM 5.0
CVE-2025-52567
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versi…
Glpi
10.0.19+
MEDIUM 5.4
CVE-2025-27514
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versi…
Glpi
10.0.19+
HIGH 8.8
CVE-2025-24801EPSS 20%
GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI …
Glpi
10.0.18+
CRITICAL 9.8
CVE-2025-24799EPSS 86%
GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vul…
Glpi
10.0.18+
CRITICAL 9.8
CVE-2025-21619
GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This…
Glpi
10.0.18+
HIGH 7.5
CVE-2025-23046
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.18, if a "Mail servers" authentication p…
Glpi
10.0.18+
MEDIUM 6.5
CVE-2025-25192
GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive i…
Glpi
10.0.18+
MEDIUM 6.5
CVE-2025-21626
GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive…
Glpi
10.0.18+
MEDIUM 6.1
CVE-2024-11955
A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of t…
Glpi
10.0.18+
MEDIUM 6.1
CVE-2025-21627
GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious link can be crafted to perform a reflected XSS att…
Glpi
10.0.18+
MEDIUM 5.3
CVE-2024-50339EPSS 20%
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve…
Glpi
10.0.17+
HIGH 8.1
CVE-2024-48912
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated user can use an ap…
Glpi
10.0.17+