Vulnerabilidades em Glpi-Project
169 resultadosAnálise Vexday
GLPI-Project apresenta um perfil de risco baixo com apenas 1 vulnerabilidade catalogada e nenhuma sob exploração ativa confirmada. A fraqueza identificada (CWE-203 - Observação de Diferenças de Informações) não é classificada como crítica e não gerou novos registros nos últimos 90 dias, indicando que o risco é estável e historicamente contido.
CVE-2023-34254HIGHRemote inventory task command injection when using ssh command modeEPSS 0.8%CVE-2020-11035HIGHweak CSRF tokens in GLPIEPSS 0.8%CVE-2020-15177HIGHUnauthenticated Stored XSS in GLPIEPSS 0.8%CVE-2023-28838CRITICALGLPI vulnerable to SQL injection through dynamic reportsEPSS 0.8%CVE-2022-29250HIGHSQL injection in GLPIEPSS 0.8%CVE-2022-24869MEDIUMCross Site Scripting in GLPIEPSS 0.8%CVE-2023-41321MEDIUMSensitive fields enumeration through API in GLPIEPSS 0.7%CVE-2023-41324HIGHAccount takeover through API in GLPIEPSS 0.7%CVE-2023-41322MEDIUMPrivilege Escalation from technician to super-admin in GLPIEPSS 0.7%CVE-2023-23610MEDIUMglpi vulnerable to Unauthorized access to data exportEPSS 0.7%CVE-2022-35946MEDIUMSQL injection through plugin controller in GLPIEPSS 0.7%CVE-2022-31143MEDIUMLeak of sensitive information through login page error in GLPIEPSS 0.7%CVE-2023-37278MEDIUMGLPI vulnerable to SQL injection via dashboard administrationEPSS 0.7%CVE-2024-37147MEDIUMGLPI allows Authenticated File Upload to Restricted TicketsEPSS 0.7%CVE-2023-28632HIGHGLPI vulnerable to account takeover by authenticated userEPSS 0.7%CVE-2024-27104MEDIUMStored XSS in dashboards in GLPIEPSS 0.7%CVE-2023-35940HIGHGLPI vulnerable to unauthenticated access to Dashboard dataEPSS 0.7%CVE-2021-21258MEDIUMXSS injection in ajax/kanbanEPSS 0.7%CVE-2025-25192MEDIUMGLPI allows unauthorized access to debug modeEPSS 0.6%CVE-2021-21325MEDIUMStored XSS in budget typeEPSS 0.6%