Maintainer Pavel Zilke in the sisyphus branch: Information
Maintainer name: Pavel Zilke (zidex)
Built source packages in this branch: 4
Last changes
Feb 4, 2026, 03:40 AM
#407092 sent by Pavel Zilke
IT and asset management software
Feb. 3, 2026 Pavel Zilke:
- New version 11.0.4 - Security fixes: + CVE-2026-23624 : Session stealing on externally authenticated user change + CVE-2026-22248 : Remote Code Execution via malicious upload + CVE-2026-22247 : SSRF via Webhooks
Dec 27, 2025, 05:15 PM
#404010 sent by Pavel Zilke
IT and asset management software
Dec. 27, 2025 Pavel Zilke:
- New version 11.0.4 - Yesterday, 11.0.3 was shipped, but soon after a few annoying regressions has been detected, and so a need for new release. - This release fixes a security issue that has been recently discovered. Update is recommended! - Security fixes: + CVE-2025-64516 : Unauthorized access to documents + CVE-2025-66417 : Unauthenticated SQL injection
Nov 8, 2025, 03:32 PM
#399574 sent by Pavel Zilke
Oct 12, 2025, 04:12 AM
#396719 sent by Pavel Zilke
Oct 1, 2025, 11:11 PM
#396234 sent by Pavel Zilke
IT and asset management software
Oct. 1, 2025 Pavel Zilke:
- New version 11.0.0 - Deleted glpi-php8.1
Sep 19, 2025, 11:27 PM
#395356 sent by Pavel Zilke
IT and asset management software
Sept. 12, 2025 Pavel Zilke:
- New version 10.0.20 - Added glpi-php8.4 (ALT #55848)
Aug 22, 2025, 11:20 PM
#393043 sent by Pavel Zilke
IT Operations Portal
Aug. 22, 2025 Pavel Zilke:
- New version 3.2.2 - Security fixes: + CVE-2025-47286 : Remote Code Execution in the backup creation functionality + CVE-2025-49145 : Webhooks: check that callbacks signatures meet the documented expectation
Aug 2, 2025, 01:55 PM
#391564 sent by Pavel Zilke
IT and asset management software
July 16, 2025 Pavel Zilke:
- New version 10.0.19 - This release fixes a security issue that has been recently discovered. Update is recommended! - Security fixes: + CVE-2025-27514 : Stored XSS on projects kanban + CVE-2025-52567 : Blind SSRF in RSS feeds and planning + CVE-2025-52897 : XSS and open redirection in planning + CVE-2025-53008 : Mail receiver credentials exfiltration + CVE-2025-53357 : Reservations modification by unauthorized user + CVE-2025-53113 : Access to unallowed items information through external links + CVE-2025-53111 : Data exposure to non allowed users + CVE-2025-53112 : Data removal from allowed users + CVE-2025-53105 : Unauthorized rules execution order update
Jun 29, 2025, 09:00 PM
#388451 sent by Pavel Zilke
IT Operations Portal
June 29, 2025 Pavel Zilke:
- New version 3.2.1.1 - Security fixes: + CVE-2024-52601 : Secure Direct Object Reference + prevent Mass Data Leak + CVE-2025-24021 : Prevent mass assignment of fields not present in form + CVE-2025-24022 : Prevent Portal code injection + CVE-2025-24026 : Fix redos in regex (snyk.io) + CVE-2024-56157 : Fix self XSS in CSV Import
Mar 11, 2025, 01:31 AM
#377585 sent by Pavel Zilke
IT and asset management software
Feb. 12, 2025 Pavel Zilke:
- New version 10.0.18 - This release fixes a security issue that has been recently discovered. Update is recommended! - Security fixes: + CVE-2025-24799 : Unauthenticated SQL injection through the inventory endpoint + CVE-2025-24801 : Authenticated Remote code execution + CVE-2025-21619 : SQL injection through the rules configuration + CVE-2024-11955 : Open Redirection + CVE-2025-21627 : Reflected XSS in search page + CVE-2025-21626 : Exposure of sensitive information in the status.php endpoint + CVE-2025-23024 : Plugins disabled by unauthenticated user + CVE-2025-23046 : Unauthorized authentication by email using the OAuthIMAP plugin + CVE-2025-25192 : Unauthorized access to debug mode
Jan 17, 2025, 04:17 PM
#369847 sent by Pavel Zilke
IT Operations Portal
Jan. 17, 2025 Pavel Zilke:
- New version 3.2.0.2 - Added itop-php8.2 - Added itop-php8.3 - Security fixes: + CVE-2023-46734 : Potential XSS vulnerabilities in TWIG CodeExtension filters + CVE-2023-45808 : Can create objects in non allowed org by forging http query in both Console and Portal + CVE-2023-43790 : XSS in friendlyname in object details + CVE-2023-44396 : XSS vulnerabilities in dashlet ajax operations + CVE-2023-47626 : Fix stored XSS in authent token + CVE-2023-48709 : Fix CSV injection in Excel from an iTop CSV export file + CVE-2023-48710 : Limit pages/exec.php script to PHP files + CVE-2024-31448 : Fix XSS vulnerability in link CSV import + CVE-2024-32870 : itop hub connector Information disclosure
Nov 8, 2024, 01:48 AM
#361983 sent by Pavel Zilke
IT and asset management software
Nov. 8, 2024 Pavel Zilke:
- New version 10.0.17 - Added glpi-php8.3 - This release fixes a security issue that has been recently discovered. Update is recommended! - Security fixes: + CVE-2024-50339 : Unauthenticated session hijacking + CVE-2024-40638 : Account takeover through SQL injection + CVE-2024-43416 : Users email enumeration by unauthenticated user + CVE-2024-47758 : Account takeover without privilege escalation through the API + CVE-2024-47761 : Account takeover via the password reset feature + CVE-2024-47760 : Account takeover via API + CVE-2024-48912 : Insecure account deletion by authenticated user + CVE-2024-45608 : Authenticated SQL Injection + CVE-2024-41679 : Authenticated SQL injection in ticket form + CVE-2024-45611 : Stored XSS in RSS feeds + CVE-2024-47759 : Stored XSS via document upload + CVE-2024-43417 : Reflected XSS + CVE-2024-43418 : Reflected XSS + CVE-2024-45609 : Reflected XSS + CVE-2024-45610 : Reflected XSS + CVE-2024-41678 : Reflected XSS
Jul 3, 2024, 11:47 PM
#352107 sent by Pavel Zilke
IT and asset management software
July 3, 2024 Pavel Zilke:
- New version 10.0.16 - This release fixes a security issue that has been recently discovered. Update is recommended! - Security fixes: + CVE-2024-37148 : Account takeover via SQL Injection in AJAX scripts + CVE-2024-37149 : Remote code execution through the plugin loader + CVE-2024-37147 : Authenticated file upload to restricted tickets
Apr 26, 2024, 11:25 PM
#345902 sent by Pavel Zilke
IT and asset management software
April 26, 2024 Pavel Zilke:
- New version 10.0.15 - This release fixes a security issue that has been recently discovered. Update is recommended! - Security fixes: + CVE-2024-31456 Authenticated SQL injection from map search + CVE-2024-29889 Account takeover via SQL Injection in saved searches feature
Mar 25, 2024, 11:34 PM
#343562 sent by Pavel Zilke
IT and asset management software
March 25, 2024 Pavel Zilke:
- New version 10.0.14 - Due to a few regressions in the last (10.0.13), an early release is available.
Feb 18, 2024, 05:37 PM
#340947 sent by Pavel Zilke
IT and asset management software
Feb. 2, 2024 Pavel Zilke:
- New version 10.0.12 - This release fixes a security issue that has been recently discovered. Update is recommended! - Security fixes: + CVE-2024-23645 : Reflected XSS in reports pages + CVE-2023-51446 : LDAP Injection during authentication ()
Jan 4, 2024, 11:22 AM
#337677 sent by Pavel Zilke
IT Operations Portal
Jan. 4, 2024 Pavel Zilke:
- New version 3.1.1.1 - Security fixes: + CVE-2023-48710 : Restrict pages/exec.php to PHP files + CVE-2023-48709 : Fix CSV injection in Excel from an iTop CSV export file + CVE-2023-46734 : Fix potential XSS vulnerabilities in TWIG CodeExtension filters + CVE-2023-47123 : Fix XSS vulnerability in n:n relations "tagset" widget + CVE-2023-47622 : Fix XSS vulnerabilities in ajax operations + CVE-2023-47626 : Fix XSS vulnerabilities in authent token + CVE-2023-44396 : Fix XSS vulnerabilities in dashlet ajax operations + CVE-2023-43790 : Fix XSS vulnerabilities in friendlyname in object details + CVE-2023-38511 : Fix dashboard allowing to load multiple files and urls + CVE-2023-45808 : Fix object creation in non allowed org by forging http query in both Console and Portal
Dec 19, 2023, 11:54 AM
#336741 sent by Pavel Zilke
Dec 15, 2023, 12:35 AM
#336499 sent by Pavel Zilke
IT and asset management software
Dec. 14, 2023 Pavel Zilke:
- New version 10.0.11 - This release fixes a security issue that has been recently discovered. Update is recommended! - Security fixes: + CVE-2023-43813 : Authenticated SQL Injection + CVE-2023-46727 : SQL injection through inventory agent request + CVE-2023-46726 : Remote code execution from LDAP server configuration form on PHP 7.4 - Deleted glpi-php8.0
Oct 7, 2023, 12:52 AM
#331146 sent by Pavel Zilke
IT and asset management software
Oct. 1, 2023 Pavel Zilke:
- New version 10.0.10 - This release fixes a security issue that has been recently discovered. Update is recommended! - Security fixes: + CVE-2023-42802 : Unallowed PHP script execution + CVE-2023-41320 : Account takeover via SQL Injection in UI layout preferences + CVE-2023-41326 : Account takeover via Kanban feature + CVE-2023-41324 : Account takeover through API + CVE-2023-42462 : File deletion through document upload process + CVE-2023-41321 : Sensitive fields enumeration through API + CVE-2023-41322 : Privilege Escalation from technician to super-admin + CVE-2023-41323 : Users login enumeration by unauthenticated user + CVE-2023-41888 : Phishing through a login page malicious URL + CVE-2023-42461 : SQL injection in ITIL actors
Oct 7, 2023, 12:34 AM
#331144 sent by Pavel Zilke
IT Operations Portal
Aug. 11, 2023 Pavel Zilke:
- New version 3.1.0.2 - Security fixes: + CVE-2022-24894 : Prevent storing cookie headers in HttpCache (Symfony framework vulnerability) + CVE-2022-31402 : XSS vulnerability via /itop/webservices/export-v2.php + CVE-2022-39261 : Twig lib vulnerability - Added itop-php8.1 - Deleted itop-php8.0
Jul 26, 2023, 12:16 AM
#325568 sent by Pavel Zilke
IT and asset management software
July 13, 2023 Pavel Zilke:
- New version 10.0.9 - This release fixes several security issues that has been recently discovered. Update is recommended! - Security fixes: + CVE-2023-37278 : SQL injection in dashboard administration - Deleted glpi-php7
May 25, 2023, 06:45 PM
#321861 sent by Pavel Zilke
IT Operations Portal
May 25, 2023 Pavel Zilke:
- New version 3.0.3 - Security fixes: + CVE-2021-46743 : Firebase PHP-JWT key/algorithm type confusion + CVE-2022-31403 : XSS vulnerability via /itop/pages/ajax.render.php + CVE-2022-31402 : XSS vulnerability via /itop/webservices/export-v2.php - Added itop-php8.0 - Deleted itop-php7
May 15, 2023, 11:22 AM
#320515 sent by Pavel Zilke
IT and asset management software
May 13, 2023 Pavel Zilke:
- New version 10.0.7 - This release fixes several security issues that has been recently discovered. Update is recommended! - Security fixes: + CVE-2023-28849 : SQL injection and Stored XSS via inventory agent request + CVE-2023-28632 : Account takeover by authenticated user + CVE-2023-28838 : SQL injection through dynamic reports + CVE-2023-28852 : Stored XSS through dashboard administration + CVE-2023-28636 : Stored XSS on external links + CVE-2023-28639 : Reflected XSS in search pages + CVE-2023-28634 : Privilege Escalation from technician to super-admin + CVE-2023-28633 : Blind Server-Side Request Forgery (SSRF) in RSS feeds
Mar 18, 2023, 01:08 PM
#316952 sent by Pavel Zilke
IT and asset management software
Jan. 24, 2023 Pavel Zilke:
- New version 10.0.6 - This release fixes several security issues that has been recently discovered. Update is recommended! - Security fixes: + CVE-2023-22500 : Unauthorized access to inventory files + CVE-2023-22722 : XSS on browse views + CVE-2023-22725 : XSS on external links + CVE-2023-22724 : XSS in RSS Description Link + CVE-2023-23610 : Unauthorized access to data export + CVE-2022-41941 : Stored XSS inside Standard Interface Help Link href attribute - Added glpi-php8.2
Nov 4, 2022, 09:56 PM
#309499 sent by Pavel Zilke
IT and asset management software
Nov. 4, 2022 Pavel Zilke:
- New version 10.0.4 - This release fixes several security issues that has been recently discovered. Update is recommended! - Security fixes: + CVE-2022-39276 : Blind SSRF in RSS feeds and planning + CVE-2022-39372 : Stored XSS in user information + CVE-2022-39373 : Stored XSS in entity name + CVE-2022-39376 : Improper input validation on emails links + CVE-2022-39370 : Improper access to debug panel + CVE-2022-39234 : User's session persist after permanently deleting his account + CVE-2022-39262 : Stored XSS on login page + CVE-2022-39277 : XSS in external links + CVE-2022-39375 : XSS through public RSS feed + CVE-2022-39323 : SQL Injection on REST API + CVE-2022-39371 : Stored XSS through asset inventory
Sep 15, 2022, 04:08 AM
#306812 sent by Pavel Zilke
IT and asset management software
Sept. 14, 2022 Pavel Zilke:
- New version 10.0.3 - This release fixes several critical security issues that has been recently discovered. Update is strongly recommended! - Security fixes: + CVE-2022-35945 : XSS through registration API + CVE-2022-31143 : Leak of sensitive information through login page error + CVE-2022-31187 : Stored XSS through global search (CVE-2022-31187) + CVE-2022-35914 : [critical] Command injection using a third-party library script + CVE-2022-35946 : SQL injection through plugin controller + CVE-2022-35947 : [critical] Authentication via SQL injection + CVE-2022-36112 : Blind Server-Side Request Forgery (SSRF) in RSS feeds and planning
Jul 23, 2022, 12:03 AM
#304144 sent by Pavel Zilke
IT and asset management software
July 22, 2022 Pavel Zilke:
- New version 10.0.2 - This is a security release, upgrading is recommended - Security fixes: + CVE-2022-31061 : Unauthenticated SQL injection on login page + CVE-2022-31056 : SQL injection on actor part in assistance forms + CVE-2022-31068 : Unauthenticated Sensitive Data Exposure on Refused Inventory Files
Jun 10, 2022, 11:20 PM
#301769 sent by Pavel Zilke
IT and asset management software
June 10, 2022 Pavel Zilke:
- New version 10.0.1 - This is a security release, upgrading is recommended - The GLPI licence has been moved to GPLv3+
May 20, 2022, 11:53 PM
#300291 sent by Pavel Zilke
IT and asset management software
April 20, 2022 Pavel Zilke:
- New version 10.0.0 - Added glpi-php8.0 - Added glpi-php8.1
Mar 11, 2022, 10:50 AM
#296500 sent by Pavel Zilke
IT and asset management software
Jan. 27, 2022 Pavel Zilke:
- New version 9.5.7 - This is a security release, upgrading is recommended - Security fixes: + CVE-2022-21720 : SQL injection using custom CSS administration form + CVE-2022-21719 : Reflected XSS using reload button
Oct 13, 2021, 02:39 AM
#286922 sent by Pavel Zilke
IT and asset management software
Oct. 12, 2021 Pavel Zilke:
- New version 9.5.6 - This is a security release, upgrading is recommended - Security fixes: + CVE-2021-39211 : Disclosure of GLPI and server informations in telemetry endpoint + CVE-2021-39210 : Autologin cookie accessible by scripts + CVE-2021-39209 : Bypassable CSRF protection on ajax endpoints + CVE-2021-39213 : Bypassable IP restriction on GLPI API using custom header injection
May 13, 2021, 01:09 AM
#271713 sent by Pavel Zilke
IT and asset management software
May 13, 2021 Pavel Zilke:
- New version 9.5.5 - This is a security release, upgrading is recommended - Security fixes: + CVE-2021-3486 : Stored XSS in plugins information
Mar 31, 2021, 07:35 PM
#268732 sent by Pavel Zilke
IT and asset management software
March 31, 2021 Pavel Zilke:
- New version 9.5.4 - This is a security release, upgrading is recommended - Security fixes: + CVE-2021-21326 : Horizontal Privilege Escalation + CVE-2021-21255 : entities switch IDOR + CVE-2021-21258 : XSS injection in ajax/kanban + CVE-2021-21314 : XSS injection on ticket update + CVE-2021-21312 : Stored XSS on documents + CVE-2021-21313 : XSS on tabs + CVE-2021-21325 : Stored XSS in budget type + CVE-2021-21327 : Unsafe Reflection in getItemForItemtype() + CVE-2021-21324 : Insecure Direct Object Reference (IDOR) on "Solutions"
Dec 25, 2020, 02:40 AM
#263868 sent by Pavel Zilke
IT and asset management software
Dec. 5, 2020 Pavel Zilke:
- New version 9.5.3 - This is a security release, upgrading is recommended - Security fixes: + CVE-2020-27662 : Insecure Direct Object Reference on ajax/comments.php + CVE-2020-27663 : Insecure Direct Object Reference on ajax/getDropdownValue.php + CVE-2020-26212 : Any CalDAV calendars is read-only for every authenticated user
Oct 27, 2020, 02:25 PM
#260499 sent by Pavel Zilke
Jul 13, 2020, 10:29 PM
#254895 sent by Pavel Zilke
IT and asset management software
June 7, 2020 Pavel Zilke:
- New version 9.4.6 - This is a security release, upgrading is highly recommended
Apr 9, 2020, 09:59 PM
#249700 sent by Pavel Zilke
IT Operations Portal
April 9, 2020 Pavel Zilke:
- New version 2.6.3 - Security fixes: + CVE-2019-19821 : Improper Privilege Management - Removed Python requirements
Dec 29, 2019, 08:03 AM
#243687 sent by Pavel Zilke
Jun 25, 2019, 10:27 AM
#233139 sent by Pavel Zilke
IT and asset management software
June 25, 2019 Pavel Zilke:
- New version 9.4.2 - This is a security release, upgrading is highly recommended
Apr 17, 2019, 10:01 AM
#227264 sent by Pavel Zilke
IT and asset management software
April 17, 2019 Pavel Zilke:
- New version 9.4.2 - This is a security release, upgrading is highly recommended
Apr 16, 2019, 07:39 PM
#227235 sent by Pavel Zilke
Apr 9, 2019, 07:38 PM
#226945 sent by Pavel Zilke
Mar 6, 2019, 05:29 PM
#223905 sent by Pavel Zilke
deleted ocsinventory-server
March 6, 2019 Pavel Zilke:
- package removed
Mar 6, 2019, 04:22 PM
#223902 sent by Pavel Zilke
IT Operations Portal
March 6, 2019 Pavel Zilke:
- New version 2.6.0 - Added PHP7 support - Deleted PHP5 support - Deleted Apache1 support
Mar 5, 2019, 04:30 PM
#223803 sent by Pavel Zilke
Feb 28, 2019, 12:37 PM
#223213 sent by Pavel Zilke
Feb 13, 2019, 04:35 PM
#221411 sent by Pavel Zilke
Jan 26, 2019, 07:38 AM
#219970 sent by Pavel Zilke
IT and asset management software
Dec. 30, 2018 Pavel Zilke:
- New verion 9.3.3 - PHP7 support
Sep 22, 2017, 12:11 AM