GLPI vendor intelligence
GLPI Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting GLPI products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 4
- Known exploited vulnerabilities affecting GLPI products
- In CISA KEV
- 1
- Records also listed in the official catalog
- Beyond CISA KEV
- 3
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- GLPI KEVs with sensor-observed exploitation activity
The catalog gap matters for GLPI exposure
Three of the four exploited GLPI CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss three-quarters of this vendor portfolio.
- 25%
- Covered by CISA
- 75%
- Beyond CISA
- 3
- Product families
Attested GLPI CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-24799
GLPI allows unauthenticated SQL injection through the inventory endpoint |
glpi | High | Beyond CISA | 24 Jun 2025 |
|
CVE-2022-35914
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection. |
GLPI | Confirmed | In CISA | 07 Mar 2023 |
|
CVE-2021-43778
Path traversal in GLPI barcode plugin |
barcode | High | Beyond CISA | 24 Nov 2021 |
|
CVE-2021-39211
Disclosure of GLPI and server information in telemetry endpoint |
glpi | High | Beyond CISA | 15 Sep 2021 |
No GLPI CVEs match this search or filter.
Showing 4 of 4 GLPI known exploited vulnerabilities.
Recurring weakness patterns
Exposure, limitation, and neutralization account for three mapped occurrences across this GLPI KEV portfolio.
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.