VendorsSnipeitappsnipe-itall versions
Vulnerabilities

Snipeitapp Snipe-IT

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

116CVEs
CVE-2025-63601
Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and execute system commands.
Published 2025-11-05 · Modified
9.9EPSS 0.006
CVE-2026-37709
Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component
Published 2026-05-07 · Analyzed
9.8EPSS 0.006
CVE-2026-86751
Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown
Published 2026-09-09 · Analyzed
9.6EPSS 0.003
CVE-2026-86738
Snipe-IT before 8.7.0 CSS Injection via Custom CSS
Published 2026-09-08 · Analyzed
9.3EPSS 0.003
CVE-2022-1380
Stored Cross Site Scripting vulnerability in Item name parameter in snipe/snipe-it
Published 2022-04-16 · Modified
9.1EPSS 0.008
CVE-2022-1445
Stored Cross Site Scripting vulnerability in the checked_out_to parameter in snipe/snipe-it
Published 2022-04-24 · Modified
9.0EPSS 0.008
CVE-2022-23064
Snipe-IT - Host Header Injection
Published 2022-05-02 · Modified
8.8EPSS 0.013
CVE-2022-0611
Missing Authorization in snipe/snipe-it
Published 2022-02-15 · Modified
8.8EPSS 0.012
CVE-2021-3858
Cross-Site Request Forgery (CSRF) in snipe/snipe-it
Published 2021-10-19 · Modified
8.8EPSS 0.005
CVE-2021-4130
Cross-Site Request Forgery (CSRF) in snipe/snipe-it
Published 2021-12-18 · Modified
8.8EPSS 0.005
CVE-2025-15602
Snipe-IT < 8.3.7 Mass Assignment Vulnerability Leading to Privilege Escalation
Published 2026-03-06 · Analyzed
8.8EPSS 0.005
CVE-2026-44832
Snipe-IT: Privilege Escalation via API Permissions Assignment
Published 2026-05-26 · Modified
8.8EPSS 0.003
CVE-2023-5511
Cross-Site Request Forgery (CSRF) in snipe/snipe-it
Published 2023-10-11 · Modified
8.8EPSS 0.003
CVE-2026-85617
snipe-it before 8.6.3 Authorization Bypass via Bulk Delete
Published 2026-09-04 · Analyzed
8.8EPSS 0.003
CVE-2026-55466
Snipe-IT: Stored XSS via inline-served attachment
Published 2026-07-10 · Analyzed
8.7EPSS 0.004
CVE-2024-51093
Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the Snipe-IT system.
Published 2024-11-12 · Modified
8.7EPSS 0.004
CVE-2026-86733
Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore
Published 2026-09-08 · Analyzed
8.6EPSS 0.003
CVE-2026-86762
Snipe-IT before 8.7.0 Authentication Bypass via API Middleware
Published 2026-09-09 · Analyzed
8.6EPSS 0.003
CVE-2026-86770
Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation
Published 2026-09-09 · Analyzed
8.6EPSS 0.003
CVE-2026-54329
Snipe-IT: Cross-Tenant Accessory Injection in Snipe-IT API
Published 2026-07-10 · Analyzed
8.5EPSS 0.004
CVE-2026-85616
Snipe-IT before 8.6.2 Authorization Bypass via Checkout-Acceptance
Published 2026-09-04 · Analyzed
8.5EPSS 0.002
CVE-2026-86741
Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULA
Published 2026-09-09 · Analyzed
8.5EPSS 0.002
CVE-2026-86754
Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients
Published 2026-09-09 · Analyzed
8.5EPSS 0.002
CVE-2026-86771
Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num
Published 2026-09-09 · Analyzed
8.3EPSS 0.002
CVE-2026-86750
snipe-it before 8.7.0 Authorization Bypass via API User Create/Update
Published 2026-09-09 · Analyzed
8.3EPSS 0.002
CVE-2024-5685
Broken Function Level Authorization (BFLA) in snipe/snipe-it
Published 2024-06-14 · Analyzed
8.1EPSS 0.004
CVE-2025-59713
Snipe-IT before 8.1.18 allows unsafe deserialization.
Published 2025-09-19 · Analyzed
8.1EPSS 0.004
CVE-2022-2997
Session Fixation in snipe/snipe-it
Published 2022-08-25 · Modified
8.0EPSS 0.009
CVE-2021-3961
Cross-site Scripting (XSS) - Stored in snipe/snipe-it
Published 2021-11-19 · Modified
8.0EPSS 0.008
CVE-2024-51094
An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. When an administrator later accesses the People Management page, exports the data as a CSV file, and opens it, the injected payload will be executed, allowing the attacker to exfiltrate internal system data from the CSV file to a remote server.
Published 2024-11-12 · Analyzed
8.0EPSS 0.004
CVE-2026-55516
Snipe-IT: Cross-company asset maintenance re-parenting via API update
Published 2026-07-10 · Analyzed
7.7EPSS 0.004
CVE-2022-1155
Old sessions are not blocked by the login enable function. in snipe/snipe-it
Published 2022-03-30 · Modified
7.4EPSS 0.010
CVE-2026-86746
Snipe-IT before 8.7.0 Authorization Bypass via Livewire Snapshot Replay
Published 2026-09-09 · Analyzed
7.4EPSS 0.003
CVE-2026-55452
Snipe-IT: CSV formula injection in Activity Report export
Published 2026-07-10 · Analyzed
7.3EPSS 0.002
CVE-2021-4075
Server-Side Request Forgery (SSRF) in snipe/snipe-it
Published 2021-12-06 · Modified
7.2EPSS 0.009
CVE-2026-55460
Snipe-IT: Authorization bypass on bulk editing users
Published 2026-07-10 · Modified
7.1EPSS 0.004
CVE-2026-55474
Snipe-IT: Directory traversal in displaySig
Published 2026-07-10 · Analyzed
7.1EPSS 0.003
CVE-2026-86734
Snipe-IT before 8.7.1 Denial of Service via Unbounded Note Field
Published 2026-09-08 · Analyzed
7.1EPSS 0.003
CVE-2026-86758
Snipe-IT before 8.7.0 License Key Exposure via CSV Export
Published 2026-09-09 · Analyzed
7.1EPSS 0.002
CVE-2026-48507
Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
Published 2026-06-08 · Modified
7.1EPSS 0.002
1 / 3Next →