Known vulnerabilities in GLPI

Software: GLPI
Software CPE: cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
Total vulnerabilities: 206
Public exploits: 15
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting GLPI GLPI is affected by 206 known vulnerabilities: 1 critical, 27 high, 70 medium, 108 low Critical High Medium Low

Vulnerabilities (206)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139546 - Improper Restriction of Excessive Authentication Attempts
CVE-2026-49470
CWE-307 High
No
No
11.0.8 27.07.2026 SB20260721151
#VU139545 - Authorization Bypass Through User-Controlled Key
CVE-2026-53626
CWE-639 Low
No
No
11.0.8 27.07.2026 SB20260721151
#VU139544 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-48482
CWE-22 Low
No
No
11.0.8 27.07.2026 SB20260721151
#VU139543 - Improper Access Control
CVE-2026-47679
CWE-284 Medium
No
No
10.0.26, 11.0.8 27.07.2026 SB20260721151
#VU139542 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-47678
CWE-89 Medium
No
No
10.0.26, 11.0.8 27.07.2026 SB20260721151
#VU139541 - Improper Access Control
CVE-2026-53625
CWE-284 Low
No
No
10.0.26, 11.0.8 27.07.2026 SB20260721151
#VU139540 - Improper Authentication
CVE-2026-52848
CWE-287 High
No
No
11.0.8 27.07.2026 SB20260721151
#VU139538 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-53629
CWE-89 Low
No
No
10.0.26, 11.0.8 27.07.2026 SB20260721151
#VU139537 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-53610
CWE-79 Medium
No
No
11.0.8 27.07.2026 SB20260721151
#VU139536 - Improper Access Control
CVE-2026-57152
CWE-284 Low
No
No
10.0.26, 11.0.8 27.07.2026 SB20260721151
#VU139535 - Improper Encoding or Escaping of Output
CVE-2026-55214
CWE-116 Low
No
No
11.0.8 27.07.2026 SB20260721151
#VU138963 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVE-2026-49469
CWE-90 Low
No
No
10.0.26, 11.0.8 21.07.2026 SB20260721151
#VU138962 - Improper Authorization
CVE-2026-55217
CWE-285 Low
No
No
10.0.26, 11.0.8 21.07.2026 SB20260721151
#VU138961 - Improper Authorization
CVE-2026-53628
CWE-285 Low
No
No
10.0.26, 11.0.8 21.07.2026 SB20260721151
#VU138960 - Improper Privilege Management
CVE-2026-45801
CWE-269 Low
No
No
10.0.26, 11.0.8 21.07.2026 SB20260721151
#VU138959 - Improper Access Control
CVE-2026-53627
CWE-284 Low
No
No
11.0.8 21.07.2026 SB20260721151
#VU133152 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-42321
CWE-79 Low
No
No
10.0.25 01.06.2026 SB2026051871
#VU133151 - Missing Authorization
CVE-2026-42318
CWE-862 Low
No
No
10.0.25, 11.0.7 01.06.2026 SB2026051871
#VU131691 - Improper Access Control
CVE-2026-42320
CWE-284 Low
No
No
10.0.25, 11.0.7 18.05.2026 SB2026051871
#VU131690 - Missing Authorization
CVE-2026-32312
CWE-862 Low
No
No
11.0.7 18.05.2026 SB2026051871


Showing elements 1 - 20 out of 206