GLPI Project maintains a focused portfolio of IT asset management and inventory tracking tools, including the core GLPI platform, inventory modules, and agent components, that are widely deployed across organizations for hardware and software discovery and lifecycle management. The vendor's vulnerability disclosures span a modest product line but carry significant landscape prominence due to the breadth of environments in which these tools operate and their role in managing critical infrastructure inventory. Recurring vulnerability patterns have not yet converged on a single dominant weakness class, reflecting the diverse functional scope of the platform across deployment, agent communication, and data parsing subsystems. Defenders should treat GLPI advisories as operationally relevant given the platform's visibility into organizational infrastructure; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Glpi Project over time
Signals from CVEs in this vendor scope (206 CVEs).
206 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-35914CRITICAL /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection. | Sep 19, 2022 | 9.8 | 99 | YES | YES |
CVE-2025-24799CRITICAL GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18. | Mar 18, 2025 | 9.8 | 90 | NO | YES |
CVE-2021-43778HIGH Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal | Nov 24, 2021 | 7.5 | 66 | NO | YES |
CVE-2024-29889HIGH GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter an | May 7, 2024 | 8.1 | 65 | NO | YES |
CVE-2023-46727CRITICAL GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attac | Dec 13, 2023 | 9.8 | 64 | NO | NO |
CVE-2020-15175CRITICAL In GLPI before version 9.5.2, the `pluginimage.send.php` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete the | Oct 7, 2020 | 9.1 | 63 | NO | NO |
CVE-2023-35924CRITICAL GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory endpoint can be used to drive a SQL injection attack | Jul 5, 2023 | 9.8 | 60 | NO | NO |
CVE-2022-31061CRITICAL GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL inj | Jun 28, 2022 | 9.8 | 60 | NO | NO |
CVE-2023-36808CRITICAL GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used | Jul 5, 2023 | 9.8 | 57 | NO | NO |
CVE-2024-27096MEDIUM GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can exploit a SQL | Mar 18, 2024 | 6.5 | 50 | NO | NO |
Signals from CVEs in this vendor scope (206 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Glpi Project.
Media articles that mention a CVE ID that affects a product developed by Glpi Project — matched by CVE ID, not by vendor name.