CVE-2025-32786: GLPI Inventory Plugin is Vulnerable to Unauthenticated SQL Injection
Published Nov 4, 2025
·Updated
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Versions 1.5.0 and below are vulnerable to SQL Injection. This issue is fixed in version 1.5.1.
Affected Software
1 affected component
GLPI Inventory Plugin<=1.5.0
Event History
Nov 4, 2025
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-32786?
CVE-2025-32786 has a critical severity due to its SQL Injection vulnerability that can lead to unauthorized data access.
2
How do I fix CVE-2025-32786?
To fix CVE-2025-32786, upgrade the GLPI Inventory Plugin to version 1.5.1 or later.
3
Which versions are affected by CVE-2025-32786?
CVE-2025-32786 affects versions of the GLPI Inventory Plugin up to and including 1.5.0.
4
What does CVE-2025-32786 affect?
CVE-2025-32786 affects the GLPI Inventory Plugin, specifically its network discovery and data collection functionalities.
5
Is there a patch for CVE-2025-32786?
Yes, patching for CVE-2025-32786 is available in version 1.5.1 of the GLPI Inventory Plugin.