Two new GLPI versions are available.
Wednesday, December 3, 11.0.3 and 10.0.21 were shipped, but soon after a few annoying regressions has been detected, and so a need for new releases.
Many bug fixes have also been made, read changelogs for more details:
You can download the new archives on GitHub:
You will find below the list of security issues fixed in theses bugfix version:
- [SECURITY - HIGH - 11.0/10.0] Unauthorized access to documents (CVE-2025-64516)
- [SECURITY - HIGH - 11.0] Unauthenticated SQL injection (CVE-2025-66417)
- [SECURITY - MODERATE - 10.0] Unauthenticated Stored XSS through the inventory endpoint (CVE-2025-59935)
- [SECURITY - MODERATE - 10.0] Unauthorized access to Knowledge Base items through the API (CVE-2025-64520)
We would like to thank all people who contributed to this new version and all those who contributes regularly to the GLPI project!
Regards.
