Glpi
Vendor:
First CVE: Aug 5, 2011 · Active for 14 years
190
Total CVEs
More Total CVEs than 99% of tracked products
12.7
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.5%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Glpi over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 5, 2011
14 years ago
Most Recent CVE
Jun 2, 2026
55 days ago
CVE Severity & Scoring
Glpi190 CVEs
57%
28%
14%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network178 (93.7%)
Unknown12 (6.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low173 (91.1%)
High5 (2.6%)
Unknown12 (6.3%)
User Interaction
None119 (62.6%)
Unknown12 (6.3%)
Required58 (30.5%)
Privileges Required
Low78 (41.1%)
High26 (13.7%)
None74 (38.9%)
Unknown12 (6.3%)
Top CVEs
Signals from CVEs in this product scope (190 CVEs).
190 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-35914CRITICAL /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection. | Sep 19, 2022 | 9.8 | 99 | YES | YES |
CVE-2025-24799CRITICAL GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18. | Mar 18, 2025 | 9.8 | 90 | NO | YES |
CVE-2024-29889HIGH GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter an | May 7, 2024 | 8.1 | 65 | NO | YES |
CVE-2023-46727CRITICAL GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attac | Dec 13, 2023 | 9.8 | 64 | NO | NO |
CVE-2020-15175CRITICAL In GLPI before version 9.5.2, the `pluginimage.send.php` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete the | Oct 7, 2020 | 9.1 | 63 | NO | NO |
CVE-2023-35924CRITICAL GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory endpoint can be used to drive a SQL injection attack | Jul 5, 2023 | 9.8 | 60 | NO | NO |
CVE-2022-31061CRITICAL GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL inj | Jun 28, 2022 | 9.8 | 60 | NO | NO |
CVE-2023-36808CRITICAL GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used | Jul 5, 2023 | 9.8 | 57 | NO | NO |
CVE-2024-27096MEDIUM GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can exploit a SQL | Mar 18, 2024 | 6.5 | 50 | NO | NO |
CVE-2022-39323CRITICAL GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and sof | Nov 3, 2022 | 9.8 | 50 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (190 CVEs).
CISA KEV
1 CVE
0.5% of CVEs· 96th percentile
Metasploit
3 CVEs
1.6% of CVEs· 96th percentile
Nuclei
5 CVEs
2.6% of CVEs· 96th percentile
ExploitDB
9 CVEs
4.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (190 CVEs).
Media Mentions
Signals from CVEs in this product scope (190 CVEs).
Top CNAs Publishing CVEs For Glpi
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.5.7 | 1 | 5.3 | 0.3% | 0 | 0 |
| 9.5.4 | 1 | 6.1 | 1.4% | 0 | 0 |
| 9.5.3 | 1 | 5.7 | 0.9% | 0 | 0 |
| 9.4.6 | 1 | 9.8 | 2.1% | 0 | 0 |
| 9.4.5 | 1 | 7.2 | 1.0% | 0 | 0 |
| 9.3.1 | 2 | 4.5 | 0.7% | 0 | 0 |
| 10.0.0 | 2 | 6.0 | 0.6% | 0 | 0 |
| 0.90.4 | 3 | 7.0 | 0.9% | 0 | 1 |
| 0.84 | 1 | 6.8 | 7.9% | 0 | 1 |
| 0.83.91 | 1 | 6.8 | 7.9% | 0 | 1 |
| 0.83.9 | 1 | 6.8 | 7.9% | 0 | 1 |
| 0.83.8 | 2 | 6.6 | 7.7% | 0 | 2 |
| 0.83.7 | 4 | 7.0 | 7.8% | 0 | 4 |
| 0.83.6 | 3 | 6.9 | 6.1% | 0 | 3 |
| 0.83.5 | 3 | 6.9 | 6.1% | 0 | 3 |
| 0.83.4 | 3 | 6.9 | 6.1% | 0 | 3 |
| 0.83.31 | 3 | 6.9 | 6.1% | 0 | 3 |
| 0.83.3 | 3 | 6.9 | 6.1% | 0 | 3 |
| 0.83.2 | 3 | 6.9 | 6.1% | 0 | 3 |
| 0.83.1 | 5 | 6.4 | 4.2% | 0 | 3 |