Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Glpi MEDIUM 6.5
CVE-2026-25937

GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor with knowledge of …

Fix: 11.0.6+
Fix from $1,600 2026-03-18
Glpi HIGH 8.8
CVE-2026-25936

GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a S…

Fix: after 11.0.6
Fix from $1,950 2026-03-17
Fields CRITICAL 9.1
CVE-2026-23489

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP …

Fix: 1.23.3+
Fix from $2,300 2026-03-16
Glpi HIGH 8.8
CVE-2026-22248

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. Fr…

Fix: 11.0.5+
Fix from $1,950 2026-03-11
Form Creator MEDIUM 5.4
CVE-2023-33971

Formcreator is a GLPI plugin which allow creation of custom forms and the creation of one or more tickets when the form is filled. A probable stored …

No fix yet
Fix from $1,600 2023-05-31
Fields MEDIUM 6.5
CVE-2023-28855

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to versions 1.13.1 and 1.20.4, lack of access control check…

Fix: 1.13.1 / 1.20.4+
Fix from $1,600 2023-04-05
System Center Configuration Manager MEDIUM 5.3
CVE-2021-39190

The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is…

Fix: 2.3.0+
Fix from $1,600 2022-09-22
Addressing CRITICAL 9.9
CVE-2021-43779EPSS 9%

GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers fro…

Fix: 2.9.1+
Fix from $2,300 2022-01-05
News MEDIUM 6.1
CVE-2019-12724

An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter.

Fix: after 1.5.2
Fix from $1,600 2019-07-10
Fields CRITICAL 9.8
CVE-2019-12723

An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and old_order parameters to ajax…

Fix: after 1.9.2
Fix from $2,300 2019-07-10
Gestionnaire Libre De Parc Informatique CRITICAL 9.8
CVE-2019-10231

Teclib GLPI before 9.4.1.1 is affected by a PHP type juggling vulnerability allowing bypass of authentication. This occurs in Auth::checkPassword() (…

Fix: 9.4.1.1+
Fix from $2,300 2019-03-27
Gestionnaire Libre De Parc Informatique CRITICAL 9.8
CVE-2019-10232EPSS 23%

Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.

Fix: after 9.3.3
Fix from $2,300 2019-03-27