CVE-2026-48482Critical· 9.4▾ MidnightGLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The i…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The imported file can be written to an executable server location, allowing a malicious script to be invoked remotely. This issue is fixed in version 11.0.8.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-47679High· 8.5GLPI is a free asset and IT management software package
CVE-2026-49469Medium· 4.6GLPI is a free asset and IT management software package
CVE-2026-45801Medium· 5.3GLPI is a free asset and IT management software package
CVE-2026-53628Medium· 5.9GLPI is a free asset and IT management software package
CVE-2026-49470High· 7.7GLPI is a free asset and IT management software package
CVE-2026-53610High· 7.5GLPI is a free asset and IT management software package