CVE-2025-53105: GLPI-Project GLPI
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 10.0.0 to before 10.0.19, a connected user without administration rights can change the rules execution order. This issue has been patched in version 10.0.19.
Affected products
- GLPI-Project GLPI: from 10.0.0, before 10.0.19 (fixed in 10.0.19)
Published 2025-08-27. Last modified 2026-06-17.