CVE-2025-53105: GLPI-Project GLPI

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 10.0.0 to before 10.0.19, a connected user without administration rights can change the rules execution order. This issue has been patched in version 10.0.19.

Affected products

  • GLPI-Project GLPI: from 10.0.0, before 10.0.19 (fixed in 10.0.19)

Published 2025-08-27. Last modified 2026-06-17.