Known vulnerabilities in GLPI - page 11
Vendor:
glpi-project
Software:
GLPI
Software CPE:
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
Website:
https://glpi-project.org/
Total vulnerabilities:
206
Public exploits:
15
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
11.0.8
10.0.26
11.0.7
10.0.25
11.0.6
10.0.24
11.0.5
10.0.23
11.0.4
10.0.22
11.0.3
10.0.21
11.0.2
11.0.1
11.0.0
10.0.20
10.0.19
10.0.18
10.0.17
10.0.16
10.0.15
10.0.14
10.0.13
10.0.12
10.0.11
10.0.10
10.0.9
10.0.8
10.0.7
9.5.13
10.0.6
9.5.12
3.0.0
10.0.5
9.5.11
10.0.4
9.5.10
10.0.3
9.5.9
10.0.2
2.0.1
10.0.1
9.5.8
10.0.0
10.0.0-rc2
9.5.7
9.5.6
9.5.5
9.5.4
9.5.3
9.5.2
0.51a
0.41
0.21
9.5.1
9.5.0
9.4.6
9.4.5
9.4.4
9.4.3
9.4.2
9.4.1.1
9.4.1
9.4.0
9.3.4
9.3.3
9.3.2
9.3.1
9.3.0
9.3
9.2.4
9.2.3
9.2.2
9.2.1
9.2
9.1.7.1
9.1.7
9.1.6
9.1.5
9.1.4
9.1.3
9.1.2
9.1.1
9.1
0.90.5
0.90.3
0.90.2
0.90.1
0.90
0.85.5
0.85.4
0.85.3
0.85.2
0.85.1
0.85
0.84.8
0.84.7
0.84.6
0.84.5
0.84.4
0.84.3
0.84.2
0.84.1
0.84
0.83.91
0.83.31
0.83.9
0.83.8
0.83.7
0.83.6
0.83.5
0.83.4
0.83.3
0.83.2
0.83.1
0.83
0.80.61
0.80.7
0.80.6
0.80.5
0.80.4
0.80.3
0.80.2
0.80.1
0.80
0.78.5
0.78.4
0.78.3
0.78.2
0.78.1
0.78
0.72.21
0.72.4
0.72.3
0.72.2
0.72.1
0.72
0.71.6
0.71.5
0.71.4
0.71.3
0.71.2
0.71.1
0.71
0.70.2
0.70.1
0.70
0.68.3
0.68.2
0.68.1
0.68
0.65
0.60
0.51
0.50
0.42
0.40
0.31
0.30
0.20.1
0.20
0.90.4
Vulnerabilities (206)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU41673 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2013-2226 |
CWE-89 | Medium | - | 14.05.2014 |
SB2014051409 SB2013062004 SB2013062005 |
||
| #VU42543 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2013-5696 |
CWE-89 | Medium | - | 23.09.2013 |
SB2013092303 SB2013091205 SB2013091206 |
||
| #VU43408 - Cross-Site Request Forgery (CSRF) CVE-2012-4002 |
CWE-352 | Medium | - | 10.10.2012 |
SB2012101006 |
||
| #VU43409 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2012-4003 |
CWE-79 | Low | 0.83.3 | 10.10.2012 |
SB2012101006 |
||
| #VU43887 - Improper Control of Generation of Code ('Code Injection') CVE-2012-1037 |
CWE-94 | Low | - | 12.07.2012 |
SB2012071205 SB2012020902 SB2012021007 |
||
| #VU44829 - Exposure of sensitive information to an unauthorized actor CVE-2011-2720 |
CWE-200 | Medium | - | 06.08.2011 |
SB2011080602 SB2011072204 SB2011072401 |
Showing elements 201 - 220 out of 206