Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
glpi-project glpi vulnerabilities and exploits
(subscribe to this query)
6.4
CVSSv2
CVE-2013-2225
inc/ticket.class.php in GLPI 0.83.9 and previous versions allows remote malicious users to unserialize arbitrary PHP objects via the _predefined_fields parameter to front/ticket.form.php.
Glpi-project Glpi
Glpi-project Glpi 0.5
Glpi-project Glpi 0.6
Glpi-project Glpi 0.20
Glpi-project Glpi 0.21
Glpi-project Glpi 0.30
Glpi-project Glpi 0.31
Glpi-project Glpi 0.40
Glpi-project Glpi 0.41
Glpi-project Glpi 0.42
Glpi-project Glpi 0.51
Glpi-project Glpi 0.51a
1 EDB exploit
6.8
CVSSv2
CVE-2012-4002
Cross-site request forgery (CSRF) vulnerability in GLPI-PROJECT GLPI prior to 0.83.3 allows remote malicious users to hijack the authentication of unspecified victims via unknown vectors.
Glpi-project Glpi
Glpi-project Glpi 0.5
Glpi-project Glpi 0.6
Glpi-project Glpi 0.20
Glpi-project Glpi 0.21
Glpi-project Glpi 0.30
Glpi-project Glpi 0.31
Glpi-project Glpi 0.40
Glpi-project Glpi 0.41
Glpi-project Glpi 0.42
Glpi-project Glpi 0.51
Glpi-project Glpi 0.51a
4.3
CVSSv2
CVE-2012-4003
Multiple cross-site scripting (XSS) vulnerabilities in GLPI-PROJECT GLPI prior to 0.83.3 allow remote malicious users to inject arbitrary web script or HTML via unknown vectors.
Glpi-project Glpi
Glpi-project Glpi 0.5
Glpi-project Glpi 0.6
Glpi-project Glpi 0.20
Glpi-project Glpi 0.21
Glpi-project Glpi 0.30
Glpi-project Glpi 0.31
Glpi-project Glpi 0.40
Glpi-project Glpi 0.41
Glpi-project Glpi 0.42
Glpi-project Glpi 0.51
Glpi-project Glpi 0.51a
5
CVSSv2
CVE-2011-2720
The autocompletion functionality in GLPI prior to 0.80.2 does not blacklist certain username and password fields, which allows remote malicious users to obtain sensitive information via a crafted POST request.
Glpi-project Glpi
Glpi-project Glpi 0.5
Glpi-project Glpi 0.6
Glpi-project Glpi 0.42
Glpi-project Glpi 0.51
Glpi-project Glpi 0.51a
Glpi-project Glpi 0.65
Glpi-project Glpi 0.68
Glpi-project Glpi 0.68.1
Glpi-project Glpi 0.68.2
Glpi-project Glpi 0.68.3
Glpi-project Glpi 0.70
6.8
CVSSv2
CVE-2013-5696
inc/central.class.php in GLPI prior to 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote malicious users to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection via an Etape_4 acti...
Glpi-project Glpi
Glpi-project Glpi 0.5
Glpi-project Glpi 0.6
Glpi-project Glpi 0.20
Glpi-project Glpi 0.21
Glpi-project Glpi 0.30
Glpi-project Glpi 0.31
Glpi-project Glpi 0.40
Glpi-project Glpi 0.41
Glpi-project Glpi 0.42
Glpi-project Glpi 0.51
Glpi-project Glpi 0.51a
2 EDB exploits
6.5
CVSSv2
CVE-2012-1037
PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 up to and including 0.80.61 allows remote authenticated users to execute arbitrary PHP code via a URL in the sub_type parameter.
Glpi-project Glpi 0.78
Glpi-project Glpi 0.78.1
Glpi-project Glpi 0.78.2
Glpi-project Glpi 0.78.3
Glpi-project Glpi 0.78.4
Glpi-project Glpi 0.78.5
Glpi-project Glpi 0.80
Glpi-project Glpi 0.80.1
Glpi-project Glpi 0.80.2
Glpi-project Glpi 0.80.3
Glpi-project Glpi 0.80.4
Glpi-project Glpi 0.80.5
7.5
CVSSv2
CVE-2013-2226
Multiple SQL injection vulnerabilities in GLPI prior to 0.83.9 allow remote malicious users to execute arbitrary SQL commands via the (1) users_id_assign parameter to ajax/ticketassigninformation.php, (2) filename parameter to front/document.form.php, or (3) table parameter to aj...
Glpi-project Glpi
Glpi-project Glpi 0.83
Glpi-project Glpi 0.83.1
Glpi-project Glpi 0.83.2
Glpi-project Glpi 0.83.3
Glpi-project Glpi 0.83.4
Glpi-project Glpi 0.83.5
Glpi-project Glpi 0.83.6
Glpi-project Glpi 0.83.7
Glpi-project Glpi 0.83.31
1 EDB exploit
5.4
CVSSv3
CVE-2022-24876
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Kanban is a GLPI view to display Projects, Tickets, Changes or Problems on a task board. In versions before 10.0.1 a user can exploit a cros...
Glpi-project Glpi
Glpi-project Glpi 10.0.0
6.5
CVSSv3
CVE-2022-29250
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to version 10.0.1 it is possible to add extra information by SQL injection on search pages. In order to exploit this vulne...
Glpi-project Glpi
Glpi-project Glpi 10.0.0
7.2
CVSSv3
CVE-2023-34254
The GLPI Agent is a generic management agent. Prior to version 1.5, if glpi-agent is running remoteinventory task against an Unix platform with ssh command, an administrator user on the remote can manage to inject a command in a specific workflow the agent would run with the priv...
Glpi-project Glpi-agent
Glpi-project Glpi Agent
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
camera
validation
CVE-2025-39395
CVE-2025-39445
andreyk
CVE-2025-4664
ciyashop
eduma
wordpress events calendar registration & tickets
CVE-2025-39376
CVE-2025-43836
CVE-2025-4918
local
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »