CVEFinder.io

CVE-2026-32312

🔶 medium
🔍 Scan for this CVE
Summary

GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue has been fixed in version 11.0.7.

CVSS Score
4.3
Medium
EPSS Score
0.0
Exploit Probability
Published Date
2026-05-19
First Seen: 2026-05-19
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 5.4% of all 326,604 vulnerabilities in our database.

#308,897
Below average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: May 19, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2026-05-21
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Vector 4.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 2

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-25932 ⚠️ high 7.2 0.0 GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user c... 2026-04-06
CVE-2026-26026 ⛔ critical 9.1 0.1 GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administ... 2026-04-06
CVE-2026-26027 ⚠️ high 7.5 0.1 GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store... 2026-04-06
CVE-2026-26263 ⚠️ high 8.1 0.0 GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based bli... 2026-04-06
CVE-2026-29047 ⚠️ high 7.2 0.0 GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user... 2026-04-06
CVE-2026-22044 🔶 medium 6.5 0.0 GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can ... 2026-02-04
These CVEs affect the same products