VulnSea

glpi-project has 13 CVEs on record. Disclosure cadence is accelerating: 13 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 13. The median CVSS is 7.1 (high), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-862 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.1
Publish → KEV
—
Last 90 days
13 prev 0

Products

  • glpi 13
13
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

glpi-project vulnerabilities

CVEs affecting glpi-project, newest first. Open any entry for full detail, references, and exploit status.

13 CVEsRSS

CVE-2026-49469Medium· 4.6
today

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter…

▾ Sunlitglpi-project · glpivia NVD
CVE-2026-53628Medium· 5.9
today

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right can change the authentication method and disable two-factor…

▾ Sunlitglpi-project · glpivia NVD
CVE-2026-45801Medium· 5.3
today

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable debug mode. The affected user-setting update does not enforce the privilege bou…

▾ Sunlitglpi-project · glpivia NVD
CVE-2026-55214High· 8.5
today

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the stored …

▾ Twilightglpi-project · glpivia NVD
CVE-2026-53610High· 7.5
today

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without sufficient output encoding. A user who opens the crafted URL …

▾ Twilightglpi-project · glpivia NVD
CVE-2026-49470High· 7.7
today

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions per user. An attacker who has obtained a user's primary authentic…

▾ Twilightglpi-project · glpivia NVD
CVE-2026-53626High· 7.1
today

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A user can …

▾ Twilightglpi-project · glpivia NVD
CVE-2026-48482Critical· 9.4
today

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The i…

▾ Midnightglpi-project · glpivia NVD
CVE-2026-53629High· 7.1PoC
today

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that injects attacker-controlled values into a database query. This…

▾ Midnightglpi-project · glpivia NVD
CVE-2026-55217Medium· 5.3
today

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations without the required authorization fo…

▾ Sunlitglpi-project · glpivia NVD
CVE-2026-53627Medium· 6.0
today

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that the same user is normally forbidden to perform through the …

▾ Sunlitglpi-project · glpivia NVD
CVE-2026-47679High· 8.5
today

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation in the profile-picture update flow to request deletion of an attacker-selecte…

▾ Twilightglpi-project · glpivia NVD
CVE-2026-53625High· 7.5PoC
today

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using the le…

▾ Midnightglpi-project · glpivia NVD
glpi-project vulnerabilities (CVEs) · VulnSea