Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Glpi Project

First CVE: Aug 5, 2011Active for: 15 yearsTotal CVEs: 403

GLPI Project maintains a focused portfolio of IT asset management and inventory tracking tools, including the core GLPI platform, inventory modules, and agent components, that are widely deployed across organizations for hardware and software discovery and lifecycle management. The vendor's vulnerability disclosures span a modest product line but carry significant landscape prominence due to the breadth of environments in which these tools operate and their role in managing critical infrastructure inventory. Recurring vulnerability patterns have not yet converged on a single dominant weakness class, reflecting the diverse functional scope of the platform across deployment, agent communication, and data parsing subsystems. Defenders should treat GLPI advisories as operationally relevant given the platform's visibility into organizational infrastructure; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
206
Total CVEs
More Total CVEs than 100% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Glpi Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 5, 2011
14 years ago
Most Recent CVE
Jun 2, 2026
52 days ago

Products(12 total)

Top CVEs

Signals from CVEs in this vendor scope (206 CVEs).

206 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-35914CRITICAL
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
Sep 19, 20229.899YESYES
CVE-2025-24799CRITICAL
GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.
Mar 18, 20259.890NOYES
CVE-2021-43778HIGH
Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal
Nov 24, 20217.566NOYES
CVE-2024-29889HIGH
GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter an
May 7, 20248.165NOYES
CVE-2023-46727CRITICAL
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attac
Dec 13, 20239.864NONO
CVE-2020-15175CRITICAL
In GLPI before version 9.5.2, the `​pluginimage.send.php​` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete the
Oct 7, 20209.163NONO
CVE-2023-35924CRITICAL
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory endpoint can be used to drive a SQL injection attack
Jul 5, 20239.860NONO
CVE-2022-31061CRITICAL
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL inj
Jun 28, 20229.860NONO
CVE-2023-36808CRITICAL
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used
Jul 5, 20239.857NONO
CVE-2024-27096MEDIUM
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can exploit a SQL
Mar 18, 20246.550NONO
View all 206 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products206 CVEs
56%
30%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (1.0%)
Network192 (93.2%)
Unknown12 (5.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low189 (91.7%)
High5 (2.4%)
Unknown12 (5.8%)
User Interaction
None133 (64.6%)
Unknown12 (5.8%)
Required60 (29.1%)
Privileges Required
Low85 (41.3%)
High27 (13.1%)
None82 (39.8%)
Unknown12 (5.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (206 CVEs).

CISA KEV
1 CVE
0.5% of CVEs· 99th percentile
Metasploit
3 CVEs
1.5% of CVEs· 97th percentile
Nuclei
6 CVEs
2.9% of CVEs· 95th percentile
ExploitDB
13 CVEs
6.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Glpi Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Glpi Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Glpi Project's Products

View all 9 CNAs →

Top CWEs