Known Vulnerabilities for GLPI 11 by Tag Plugin
Listed below are 10 of the newest known vulnerabilities associated with "GLPI 11" by "Tag Plugin".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-55217 json | GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated u... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-55214 json | GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store acti... | Not Provided | 2026-09-25 | 2026-09-29 |
| CVE-2026-53987 json | The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban badge m... | Not Provided | 2026-07-09 | 2026-07-20 |
| CVE-2026-53629 json | GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-53628 json | GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Upd... | Not Provided | 2026-09-25 | 2026-09-30 |
| CVE-2026-53627 json | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can us... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-53626 json | GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic... | Not Provided | 2026-09-25 | 2026-09-30 |
| CVE-2026-53625 json | GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the ... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-53610 json | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboar... | Not Provided | 2026-09-25 | 2026-09-29 |
| CVE-2026-49470 json | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verificat... | Not Provided | 2026-09-25 | 2026-09-28 |