#GLPI
📦 glpi-project/phpstan-glpi 1.4.0

PHPStan rules for GLPI.

🔗 https://github.com/glpi-project/phpstan-glpi
September 28, 2026 at 3:00 PM
🛑 GLPI 11.0.9 et 10.0.27 : 12 failles patchées et un rythme de mises à jour qui s’accélère

Tous les détails par ici :
- www.it-connect.fr/glpi-11-0-9-...

#glpi #infosec #cybersecurite
September 25, 2026 at 6:01 AM
🚨 EUVD-2026-87284
📊 8.5/10
🏢 glpi-project

📝 GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path ...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87284

#cybersecurity #infosec #cve #euvd
September 25, 2026 at 8:02 PM
#NewMusicChallenge
#JuneKnowWhatIMean

(What’s It All About ) Alfie – Cilla Black
www.youtube.com/watch?v=glpI...
Cilla Black - Alfie (Live)
YouTube video by CillaBlackVEVO
www.youtube.com
June 5, 2026 at 1:52 PM
🚨 EUVD-2026-87282
📊 7.7/10
🏢 glpi-project

📝 GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not li...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87282

#cybersecurity #infosec #cve #euvd
September 25, 2026 at 8:06 PM
🚨 EUVD-2026-87280
📊 5.3/10
🏢 glpi-project

📝 GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, ...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87280

#cybersecurity #infosec #cve #euvd
September 25, 2026 at 8:02 PM
🚨 EUVD-2026-87287
📊 9.4/10
🏢 glpi-project

📝 GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustrati...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87287

#cybersecurity #infosec #cve #euvd
September 25, 2026 at 8:03 PM
🚨 EUVD-2026-87283
📊 8.5/10
🏢 glpi-project

📝 GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier we...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87283

#cybersecurity #infosec #cve #euvd
September 25, 2026 at 8:04 PM
🚨 EUVD-2026-87288
📊 7.1/10
🏢 glpi-project

📝 GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a d...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87288

#cybersecurity #infosec #cve #euvd
September 25, 2026 at 8:03 PM
🚨 EUVD-2026-87286
📊 7.5/10
🏢 glpi-project

📝 GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through t...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87286

#cybersecurity #infosec #cve #euvd
September 25, 2026 at 8:01 PM
🚨 EUVD-2026-87272
📊 4.6/10
🏢 glpi-project

📝 GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit craft...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87272

#cybersecurity #infosec #cve #euvd
September 25, 2026 at 7:01 PM
🚨 EUVD-2026-87285
📊 7.5/10
🏢 glpi-project

📝 GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87285

#cybersecurity #infosec #cve #euvd
September 25, 2026 at 8:03 PM
🚨 EUVD-2026-87273
📊 6.0/10
🏢 glpi-project

📝 GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to pe...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87273

#cybersecurity #infosec #cve #euvd
September 25, 2026 at 7:01 PM
🚨 EUVD-2026-87289
📊 7.1/10
🏢 glpi-project

📝 GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87289

#cybersecurity #infosec #cve #euvd
September 25, 2026 at 8:03 PM
CVE-2026-53610 - glpi
Versions of GLPI from 11.0.0 through 11.0.8 allow a specially‑made web address to display content that the attacker supplies. If a user clicks that link, the malicious content can…

Too many irrelevant or confusing CVEs? Use stackflag.com

#glpi #glpiproject #CVE #infosec
CVE-2026-53610: GLPI: Reflected XSS in dashboards
GLPI is a free asset and IT management software package.
stackflag.com
September 26, 2026 at 3:20 PM
CVE-2026-48482 - glpi
Versions 11.0.0 through 11.0.7 of the GLPI IT management tool let a user with form‑admin rights upload a specially crafted image that is saved outside the intended folder. This can…

Too many irrelevant or confusing CVEs? Use stackflag.com

#glpi #glpiproject #CVE #infosec
CVE-2026-48482: GLPI: RCE via Form import
GLPI is a free asset and IT management software package.
stackflag.com
September 26, 2026 at 3:30 PM
CVE-2026-55214 - glpi
In GLPI versions 11.0.6 through 11.0.8, a logged‑in technician can place hidden code in the supplier information fields. When any user opens the supplier list for that item, the hidden…

Too many irrelevant or confusing CVEs? Use stackflag.com

#glpi #glpiproject #CVE #infosec
CVE-2026-55214: GLPI: Stored XSS in suppliers
GLPI is a free asset and IT management software package.
stackflag.com
September 26, 2026 at 3:10 PM
CVE-2026-53625 - glpi
In GLPI versions up to 10.0.26 and 11.0.8, a technician can use the API to alter another user's login type, even a super‑admin's. This could let the technician take over that account.…

Too many irrelevant or confusing CVEs? Use stackflag.com

#glpi #glpiproject #CVE #infosec
CVE-2026-53625: GLPI: Privilege Escalation via authtype API manipulation
GLPI is a free asset and IT management software package.
stackflag.com
September 26, 2026 at 3:20 PM
September 27, 2026 at 6:38 PM
4. Vulns : MongoDB, noyau Linux (Ubuntu/Debian/Red Hat/SUSE), GitLab, GLPI… et MongoDB exposé : 16 000+ bases Supabase mal configurées (PII, tokens) accessibles. https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/
September 29, 2026 at 5:57 AM
[Backport release-26.05] glpi-agent: 1.19 -> 1.20

https://github.com/NixOS/nixpkgs/pull/567587

#security
September 27, 2026 at 9:07 PM
Ça faisait longtemps que je n'avais pas vu de vulnérabilité pour GLPI.

Il y a 3000 instances dans le monde dont 680 en France vulnérable aux alertes CVE-2025-24799 et CVE-2025-24801. Dont la correction a été faire le 12 février 2025.

www.lemagit.fr/actualites/3...
GLPI : 680 instances en France affectées par deux graves vulnérabilités | LeMagIT
Onyphe a identifié plus de 3000 instances GLPI dans le monde affectées par deux vulnérabilités qui, enchaînées, peuvent conduire à une exécution de code arbitraire à distance. Près de 700 d’entre elle...
www.lemagit.fr
March 13, 2025 at 7:08 PM
Oui, mais y'a un ticket GLPI correctement catégorisé ou pas?
October 18, 2024 at 12:09 PM
Pre-authentication SQL injection to RCE in GLPI (CVE-2025-24799 /CVE-2025-24801)


blog.lexfo.fr ->

GLPI: "The most complete open source service management software"


Original->
March 12, 2025 at 11:30 AM