A new version of GLPI is available!
This version fixes several security issues that were recently discovered. Updating is recommended!
The GLPI version 10.0.18 archive is available on GitHub.
Below is the list of fixed security issues (none of them rated CRITICAL) in this version:
- SQL injection by an unauthenticated user via the inventory API (CVE-2025-24799)
- Remote code execution by an authenticated user (CVE-2025-24801)
- SQL injection via business rule configuration (CVE-2025-21619)
- Open redirection (CVE-2024-11955)
- Reflected XSS in the search page (CVE-2025-21627)
- Exposure of sensitive information in the `status.php` script (CVE-2025-21626)
- Plugin deactivation by an unauthenticated user (CVE-2025-23024)
- Unauthorized email authentication through the OAuthIMAP plugin (CVE-2025-23046)
- Unauthorized access to debug mode (CVE-2025-25192)
Numerous bug fixes were also made - see the full changelog for more details.
We thank everyone who contributed to this new version and all those who support the GLPI project regularly.
Best regards.