CVE-2026-53629
— UNSCOREDpublic exploit availablePublished 2026-09-25 · Updated 2026-09-25
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that injects attacker-controlled values into a database query. This permits SQL injection through the history tab endpoint. This issue is fixed in versions 11.0.8 and 10.0.26.
Weaknesses
CWE-89
Public exploit & PoC references
- https://github.com/glpi-project/glpi/commit/1296798fb03295d07c1d97fa8483d1dbab59fef5
- https://github.com/glpi-project/glpi/commit/80b86c0dcad2f6ece9b5da445d1c264a1dda3ce5
- https://github.com/glpi-project/glpi/releases/tag/10.0.26
- https://github.com/glpi-project/glpi/releases/tag/11.0.8
- https://github.com/glpi-project/glpi/security/advisories/GHSA-cpcj-x335-5cmh
All references
- https://github.com/glpi-project/glpi/commit/1296798fb03295d07c1d97fa8483d1dbab59fef5
- https://github.com/glpi-project/glpi/commit/80b86c0dcad2f6ece9b5da445d1c264a1dda3ce5
- https://github.com/glpi-project/glpi/releases/tag/10.0.26
- https://github.com/glpi-project/glpi/releases/tag/11.0.8
- https://github.com/glpi-project/glpi/security/advisories/GHSA-cpcj-x335-5cmh
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2015-20122
- HIGHCVE-2019-25776PoC
- HIGHCVE-2021-48008
- HIGHCVE-2022-4997
- CRITICALCVE-2023-54399
- CRITICALCVE-2023-54400PoC
- CRITICALCVE-2025-63564
- MEDIUMCVE-2026-100312PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.