Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Bzhunt

#10422of 53,625
26.6Total CVSS
Vulnerabilities · 3
High
1
Critical
2
PT-2026-30608
9.1
2026-04-06
Glpi · Glpi · CVE-2026-26026
Name of the Vulnerable Software and Affected Versions GLPI versions 11.0.0 through 11.0.5 Description GLPI is an asset and IT management software package. A template injection issue, exploitable by an administrator, can lead to Remote Code Execution (RCE). Recommendations Update to version 11.0.6 or later.
PT-2026-30609
7.5
2026-04-06
Glpi · Glpi · CVE-2026-26027
**Name of the Vulnerable Software and Affected Versions** GLPI versions 11.0.0 through 11.0.5 **Description** An unauthenticated user can store a Cross-Site Scripting (XSS) payload—a technique where malicious scripts are injected into trusted websites—via the 'inventory' endpoint. **Recommendations** Update to version 11.0.6.
PT-2026-30610
10
2026-04-06
Glpi · Glpi · CVE-2026-26263
**Name of the Vulnerable Software and Affected Versions** GLPI versions 11.0.0 through 11.0.5 **Description** An unauthenticated time-based blind SQL injection exists in the Search engine. SQL injection is a flaw that allows an attacker to interfere with the queries that an application makes to its database, potentially allowing them to view or modify data they are not authorized to access. **Recommendations** Update to version 11.0.6.