Two new GLPI versions are available.
Today, we ship 11.0.5 and 10.0.23. These releases contain security fixes, and we encourage you to update
Many bug fixes have also been made, read the changelogs for more details:
You can download the new archives on GitHub:
You will find below the list of security issues fixed in theses bugfix version:
- [SECURITY - MODERATE - 10.0] Authenticated SQL Injection (CVE-2026-22044)
- [SECURITY - MODERATE - 10.0 & 11.0] Session stealing on externally authenticated user change (CVE-2026-23624)
- [SECURITY - HIGH - 11.0] Remote Code Execution via malicious upload (CVE-2026-22248)
- [SECURITY - MODERATE - 11.0] SSRF via Webhooks (CVE-2026-22247)
We would like to thank all people who contributed to this new version and all those who contribute regularly to the GLPI project!
Regards.
