CVE-2026-25936

HIGH WAF: High
CVSS 8.8 Published: 2026-03-17
CWE-89

GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injection. Version 11.0.6 fixes the issue.

WAF Coverage Analysis

SQL Injection High WAF Coverage

OWASP: A03:2021 Injection

942xxx - SQL Injection

Affected Software

VendorProductVersion
teclib-editionglpiup to 11.0.6

References

Back to CVE Database