Search CVE reports


Toggle filters

331 – 340 of 49232 results

Status is adjusted based on your filters.


CVE-2026-55217

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations without the...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-55214

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-53629

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that injects attacker-controlled values into a...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-53628

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right can change the authentication method and disable...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-53627

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that the same user is normally forbidden to perform...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-53626

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-53625

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-53610

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without sufficient output encoding. A user who opens the...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-49470

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions per user. An attacker who has obtained a user's primary...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-49469

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages