CVE-2026-22044: GLPI-Project GLPI

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This issue has been patched in version 10.0.23.

Affected products

  • GLPI-Project GLPI: from 0.85, before 10.0.23 (fixed in 10.0.23)

Published 2026-02-04. Last modified 2026-06-17.