Vulnerabilities > Glpi Project > High

DATE CVE VULNERABILITY TITLE RISK
2022-11-03 CVE-2022-39234 Insufficient Session Expiration vulnerability in Glpi-Project Glpi
GLPI stands for Gestionnaire Libre de Parc Informatique.
network
low complexity
glpi-project CWE-613
8.8
2022-04-21 CVE-2022-24867 Insufficiently Protected Credentials vulnerability in Glpi-Project Glpi
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing.
network
low complexity
glpi-project CWE-522
7.5
2021-11-24 CVE-2021-43778 Unspecified vulnerability in Glpi-Project Barcode
Barcode is a GLPI plugin for printing barcodes and QR codes.
network
low complexity
glpi-project
7.5
2021-09-15 CVE-2021-39213 Injection vulnerability in Glpi-Project Glpi
GLPI is a free Asset and IT management software package.
network
low complexity
glpi-project CWE-74
8.8
2021-09-15 CVE-2021-39209 Unspecified vulnerability in Glpi-Project Glpi
GLPI is a free Asset and IT management software package.
network
low complexity
glpi-project
8.8
2021-03-08 CVE-2021-21327 Unsafe Reflection vulnerability in Glpi-Project Glpi
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing.
network
low complexity
glpi-project CWE-470
7.5
2020-10-07 CVE-2020-15176 Unspecified vulnerability in Glpi-Project Glpi
In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing for SQL Injection to occur.
network
low complexity
glpi-project
8.6
2020-09-23 CVE-2020-11031 Unspecified vulnerability in Glpi-Project Glpi
In GLPI before version 9.5.0, the encryption algorithm used is insecure.
network
low complexity
glpi-project
7.5
2020-07-17 CVE-2020-15108 SQL Injection vulnerability in Glpi-Project Glpi
In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature.
network
low complexity
glpi-project CWE-89
7.1
2020-05-12 CVE-2020-11060 Cross-Site Request Forgery (CSRF) vulnerability in Glpi-Project Glpi
In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality.
network
low complexity
glpi-project CWE-352
8.8