Glpi

Vendor:

First CVE: Aug 5, 2011 · Active for 14 years

190
Total CVEs
More Total CVEs than 99% of tracked products
12.7
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.5%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Glpi over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 5, 2011
14 years ago
Most Recent CVE
Jun 2, 2026
55 days ago

CVE Severity & Scoring

Glpi190 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network178 (93.7%)
Unknown12 (6.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low173 (91.1%)
High5 (2.6%)
Unknown12 (6.3%)
User Interaction
None119 (62.6%)
Unknown12 (6.3%)
Required58 (30.5%)
Privileges Required
Low78 (41.1%)
High26 (13.7%)
None74 (38.9%)
Unknown12 (6.3%)

Top CVEs

Signals from CVEs in this product scope (190 CVEs).

190 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
Sep 19, 20229.899YESYES
GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.
Mar 18, 20259.890NOYES
GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter an
May 7, 20248.165NOYES
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attac
Dec 13, 20239.864NONO
In GLPI before version 9.5.2, the `​pluginimage.send.php​` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete the
Oct 7, 20209.163NONO
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory endpoint can be used to drive a SQL injection attack
Jul 5, 20239.860NONO
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL inj
Jun 28, 20229.860NONO
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used
Jul 5, 20239.857NONO
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can exploit a SQL
Mar 18, 20246.550NONO
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and sof
Nov 3, 20229.850NONO

Exploit Exposure

Signals from CVEs in this product scope (190 CVEs).

CISA KEV
1 CVE
0.5% of CVEs· 96th percentile
Metasploit
3 CVEs
1.6% of CVEs· 96th percentile
Nuclei
5 CVEs
2.6% of CVEs· 96th percentile
ExploitDB
9 CVEs
4.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (190 CVEs).

Media Mentions

Signals from CVEs in this product scope (190 CVEs).

Top CNAs Publishing CVEs For Glpi

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.5.715.30.3%00
9.5.416.11.4%00
9.5.315.70.9%00
9.4.619.82.1%00
9.4.517.21.0%00
9.3.124.50.7%00
10.0.026.00.6%00
0.90.437.00.9%01
0.8416.87.9%01
0.83.9116.87.9%01
0.83.916.87.9%01
0.83.826.67.7%02
0.83.747.07.8%04
0.83.636.96.1%03
0.83.536.96.1%03
0.83.436.96.1%03
0.83.3136.96.1%03
0.83.336.96.1%03
0.83.236.96.1%03
0.83.156.44.2%03