Glpi Project: community verdicts
2 notable / known-exploited Glpi Project CVEs the community has triaged.
ⓘ Not an exhaustive list: we focus on the findings that matter (exploited / notable). For every Glpi Project CVE, see NVD ↗.
- CVE-2022-35914CRIT 9.8KEVEPSS 100%
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
- CVE-2026-32312MED 4.3EPSS 0%
GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue has been fixed in version 11.0.7.