{"id":441392,"date":"2026-06-29T09:00:00","date_gmt":"2026-06-29T07:00:00","guid":{"rendered":"https:\/\/www.glpi-project.org\/?p=441392"},"modified":"2026-06-26T11:16:32","modified_gmt":"2026-06-26T09:16:32","slug":"security-advisory-glpi-plugins-update","status":"publish","type":"post","link":"https:\/\/www.glpi-project.org\/en\/security-advisory-glpi-plugins-update\/","title":{"rendered":"Security Advisory: Update Required for Multiple GLPI Community Plugins"},"content":{"rendered":"\n<p>We are notifying the GLPI community of several security vulnerabilities identified in a number of community plugins. Updates are available and should be deployed promptly on all affected instances.<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Affected Plugins and Vulnerabilities<\/h3>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"800\" src=\"https:\/\/www.glpi-project.org\/wp-content\/uploads\/2026\/06\/table-security-glpi-1024x800.png\" alt=\"\" class=\"wp-image-441393\" srcset=\"https:\/\/www.glpi-project.org\/wp-content\/uploads\/2026\/06\/table-security-glpi-1024x800.png 1024w, https:\/\/www.glpi-project.org\/wp-content\/uploads\/2026\/06\/table-security-glpi-300x234.png 300w, https:\/\/www.glpi-project.org\/wp-content\/uploads\/2026\/06\/table-security-glpi-768x600.png 768w, https:\/\/www.glpi-project.org\/wp-content\/uploads\/2026\/06\/table-security-glpi-15x12.png 15w, https:\/\/www.glpi-project.org\/wp-content\/uploads\/2026\/06\/table-security-glpi-1320x1031.png 1320w, https:\/\/www.glpi-project.org\/wp-content\/uploads\/2026\/06\/table-security-glpi.png 1360w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>The vulnerabilities identified cover a range of severity levels, including a critical Remote Code Execution (RCE) flaw in <strong>GenericObject<\/strong> (CVSS 8.9), multiple SQL injection and Cross-Site Scripting issues across several plugins, and access control malfunctions in <strong>Escalade<\/strong>, <strong>Credit<\/strong>, and <strong>Glpinventory<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Recommendations<\/h3>\n\n\n\n<p>We strongly recommend planning and deploying updates for all affected plugins as soon as possible on your GLPI instances, in order to maintain an optimal level of security and reduce the risk of exploitation.<\/p>\n\n\n\n<p>Priority should be given to <strong>GenericObject<\/strong> (CVSS 8.9 \u2013 Critical), as it exposes instances to remote code execution.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">GLPI Network Cloud Platforms<\/h3>\n\n\n\n<p>All fixes related to the plugins listed above have already been deployed on <strong>GLPI Network Cloud Public<\/strong> and <strong>GLPI Network Cloud Private<\/strong> platforms. No action is required for instances hosted in our managed environments.<\/p>\n\n\n\n<p>Should you require technical assistance or additional information, please <a href=\"https:\/\/glpi-project.org\/contact\/\">contact us<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We are notifying the GLPI community of several security vulnerabilities identified in a number of community plugins. Updates are available and should be deployed promptly on all affected instances. Affected Plugins and Vulnerabilities The vulnerabilities identified cover a range of severity levels, including a critical Remote Code Execution (RCE) flaw in GenericObject (CVSS 8.9), multiple [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":441394,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[153],"tags":[],"class_list":["post-441392","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-produits"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.glpi-project.org\/en\/wp-json\/wp\/v2\/posts\/441392","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.glpi-project.org\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.glpi-project.org\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.glpi-project.org\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.glpi-project.org\/en\/wp-json\/wp\/v2\/comments?post=441392"}],"version-history":[{"count":8,"href":"https:\/\/www.glpi-project.org\/en\/wp-json\/wp\/v2\/posts\/441392\/revisions"}],"predecessor-version":[{"id":441405,"href":"https:\/\/www.glpi-project.org\/en\/wp-json\/wp\/v2\/posts\/441392\/revisions\/441405"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.glpi-project.org\/en\/wp-json\/wp\/v2\/media\/441394"}],"wp:attachment":[{"href":"https:\/\/www.glpi-project.org\/en\/wp-json\/wp\/v2\/media?parent=441392"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.glpi-project.org\/en\/wp-json\/wp\/v2\/categories?post=441392"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.glpi-project.org\/en\/wp-json\/wp\/v2\/tags?post=441392"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}