Glpi
214 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Glpi, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Glpi CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 12 |
| 2024-12 | 5 |
| 2025-01 | 0 |
| 2025-02 | 6 |
| 2025-03 | 3 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 8 |
| 2025-08 | 1 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 3 |
| 2026-01 | 2 |
| 2026-02 | 3 |
| 2026-03 | 4 |
| 2026-04 | 5 |
| 2026-05 | 1 |
| 2026-06 | 8 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 13 |
Severity
How the 214 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical14
- High64
- Medium107
- Low9
Latest CVEs
The 15 most recently published vulnerabilities affecting Glpi.
- CVE-2026-53629GLPI: SQL injection in history tab—
- CVE-2026-53626GLPI: Arbitrary Document Read via Form Context Authorization Bypass—
- CVE-2026-48482GLPI: RCE via Form import—
- CVE-2026-53625GLPI: Privilege Escalation via authtype API manipulation—
- CVE-2026-53610GLPI: Reflected XSS in dashboards—
- CVE-2026-47679GLPI: arbitrary file deletion—
- CVE-2026-55214GLPI: Stored XSS in suppliers—
- CVE-2026-49470GLPI: Missing Rate Limiting on Login and TOTP Verification — Account Takeover via Brute Force—
- CVE-2026-55217GLPI: Unallowed modfication of knowbase items comments and translations—
- CVE-2026-53628GLPI: Unallowed authentication method update by administrator—
- CVE-2026-45801GLPI: Unauthorized Debug Mode Activation via Profile Update (Privilege Escalation)—
- CVE-2026-53627GLPI: Unexpected access to update operations through the API—
- CVE-2026-49469GLPI: LDAP filter injection in user import feature—
- CVE-2026-13490glpi-project glpi Document document.send.php canViewFile authorization3.7
- CVE-2026-42321GLPI has stored XSS in asset locks—
Product grouping is registry-driven, with AI assist and human review. How it works