CVE-2026-22247 – GLPI is Vulnerable to SSRF via Webhooks
CVE ID : CVE-2026-22247
Published : Feb. 4, 2026, 6:16 p.m. | 1 hour, 2 minutes ago
Description : GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issue has been patched in version 11.0.5.
Severity: 4.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more…