Vulnerabilities > Glpi Project > Glpi

DATE CVE VULNERABILITY TITLE RISK
2022-09-19 CVE-2022-35914 Injection vulnerability in Glpi-Project Glpi
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
network
low complexity
glpi-project CWE-74
critical
9.8
2022-06-28 CVE-2022-31056 SQL Injection vulnerability in Glpi-Project Glpi 10.0.0/10.0.1
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.
network
low complexity
glpi-project CWE-89
7.5
2022-06-28 CVE-2022-31061 SQL Injection vulnerability in Glpi-Project Glpi
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.
network
low complexity
glpi-project CWE-89
7.5
2022-06-28 CVE-2022-31068 Unspecified vulnerability in Glpi-Project Glpi 10.0.0/10.0.1
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.
network
low complexity
glpi-project
5.0
2022-06-09 CVE-2022-29250 SQL Injection vulnerability in Glpi-Project Glpi 10.0.0
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing.
network
low complexity
glpi-project CWE-89
4.0
2022-06-09 CVE-2022-24876 Cross-site Scripting vulnerability in Glpi-Project Glpi 10.0.0
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing.
3.5
2022-04-21 CVE-2022-24867 Insufficiently Protected Credentials vulnerability in Glpi-Project Glpi
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing.
network
low complexity
glpi-project CWE-522
7.8
2022-04-21 CVE-2022-24868 Cross-site Scripting vulnerability in Glpi-Project Glpi
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing.
3.5
2022-04-21 CVE-2022-24869 Cross-site Scripting vulnerability in Glpi-Project Glpi
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing.
3.5
2022-03-28 CVE-2021-44617 SQL Injection vulnerability in Glpi-Project Glpi 9.4.6
A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.
network
low complexity
glpi-project CWE-89
7.5