VendorsSnipeitappsnipe-itall versions
Vulnerabilities

Snipeitapp Snipe-IT

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

116CVEs
CVE-2026-86765
Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint
Published 2026-09-09 · Analyzed
7.1EPSS 0.004
CVE-2026-86757
Snipe-IT before 8.7.0 Information Disclosure via Custom Fields
Published 2026-09-09 · Analyzed
7.1EPSS 0.004
CVE-2026-86764
Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components
Published 2026-09-09 · Analyzed
7.1EPSS 0.004
CVE-2026-86759
Snipe-IT before 8.7.0 Missing Authorization via asset-history CSV importer
Published 2026-09-09 · Analyzed
7.1EPSS 0.004
CVE-2026-86766
Snipe-IT 8.6.3 Race Condition via Consumable Checkout
Published 2026-09-09 · Analyzed
7.1EPSS 0.003
CVE-2026-44833
Snipe-IT: Open redirect vulnerability
Published 2026-05-26 · Analyzed
7.1EPSS 0.002
CVE-2026-55843
Snipe-IT: Improper Privilege Management
Published 2026-07-10 · Analyzed
7.0EPSS 0.005
CVE-2026-86749
snipe-it before 8.7.0 Data Loss via Failed Image Write
Published 2026-09-09 · Analyzed
7.0EPSS 0.003
CVE-2026-86748
Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive
Published 2026-09-09 · Analyzed
6.9EPSS 0.004
CVE-2021-3879
Cross-site Scripting (XSS) - Stored in snipe/snipe-it
Published 2021-10-19 · Modified
6.8EPSS 0.008
CVE-2024-48987
Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.
Published 2024-10-11 · Analyzed
6.6EPSS 0.010
CVE-2022-1511
Missing Authorization in snipe/snipe-it
Published 2022-04-28 · Modified
6.5EPSS 0.011
CVE-2022-0579
Missing Authorization in snipe/snipe-it
Published 2022-02-14 · Modified
6.5EPSS 0.011
CVE-2026-55469
Snipe-IT: Path traversal vulnerability via CSV import `image` field
Published 2026-07-10 · Analyzed
6.5EPSS 0.006
CVE-2026-38533
An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.
Published 2026-04-14 · Analyzed
6.5EPSS 0.005
CVE-2026-86742
Snipe-IT before 8.7.0 CSV Formula Injection via Asset Acceptance Report
Published 2026-09-09 · Analyzed
6.5EPSS 0.004
CVE-2026-48492
Snipe-IT's selectlist visibility is too permissive
Published 2026-07-08 · Analyzed
6.5EPSS 0.004
CVE-2026-86745
Snipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping Export
Published 2026-09-09 · Analyzed
6.5EPSS 0.004
CVE-2026-86739
Snipe-IT before 8.7.0 Acceptance Finalization Without Stored Evidence
Published 2026-09-09 · Analyzed
6.5EPSS 0.004
CVE-2021-4108
Cross-site Scripting (XSS) - Stored in snipe/snipe-it
Published 2021-12-14 · Modified
6.4EPSS 0.008
CVE-2025-59712
Snipe-IT before 8.1.18 allows XSS.
Published 2025-09-19 · Analyzed
6.4EPSS 0.003
CVE-2021-4018
Cross-site Scripting (XSS) - Stored in snipe/snipe-it
Published 2021-12-01 · Modified
6.3EPSS 0.007
CVE-2022-0179
Missing Authorization in snipe/snipe-it
Published 2022-01-12 · Modified
6.3EPSS 0.006
CVE-2022-0178
Missing Authorization in snipe/snipe-it
Published 2022-01-13 · Modified
6.3EPSS 0.006
CVE-2026-86774
Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy
Published 2026-09-09 · Analyzed
6.3EPSS 0.003
CVE-2026-55481
Snipe-IT: CSS Injection via `header_color` Setting
Published 2026-07-10 · Analyzed
6.2EPSS 0.003
CVE-2019-10118
Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta values and the user's last name in the API.
Published 2019-03-27 · Modified
6.1EPSS 0.008
CVE-2021-3863
Cross-site Scripting (XSS) - Generic in snipe/snipe-it
Published 2021-10-19 · Modified
6.1EPSS 0.008
CVE-2026-86756
Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState
Published 2026-09-09 · Analyzed
6.1EPSS 0.003
CVE-2026-55461
Snipe-IT: Open Redirect After User Edit
Published 2026-07-10 · Analyzed
6.1EPSS 0.003
CVE-2025-64027
Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an invalid CSV file is uploaded, the application returns a progress_message value that is rendered as raw HTML in the admin interface. An attacker can intercept and modify the POST /livewire/update request to inject arbitrary HTML or JavaScript into the progress_message. Because the server accepts the modified input without sanitization and reflects it back to the user, arbitrary JavaScript executes in the browser of any authenticated admin who views the import page. NOTE: this is disputed by the Supplier because the report only demonstrates that an authenticated user can choose to conduct a man-in-the-middle attack against himself.
Published 2025-11-20 · Modified
6.1EPSS 0.002
CVE-2022-3035
Cross-site Scripting (XSS) - Stored in snipe/snipe-it
Published 2022-08-29 · Modified
5.9EPSS 0.007
CVE-2026-86735
snipe-it before 8.7.0 SSRF via IPv6 transition address bypass
Published 2026-09-08 · Analyzed
5.9EPSS 0.003
CVE-2026-55475
Snipe-IT: Import created_by can be overwritten
Published 2026-07-10 · Analyzed
5.7EPSS 0.003
CVE-2023-5452
Cross-site Scripting (XSS) - Stored in snipe/snipe-it
Published 2023-10-06 · Modified
5.5EPSS 0.005
CVE-2026-48493
Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
Published 2026-06-23 · Analyzed
5.5EPSS 0.003
CVE-2021-3938
Cross-site Scripting (XSS) - Generic in snipe/snipe-it
Published 2021-11-13 · Modified
5.4EPSS 0.005
CVE-2022-44380
Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.
Published 2022-12-25 · Modified
5.4EPSS 0.005
CVE-2026-86760
snipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flag
Published 2026-09-09 · Analyzed
5.4EPSS 0.004
CVE-2026-86768
Snipe-IT before 8.7.0 Improper Input Validation via API Checkout
Published 2026-09-09 · Analyzed
5.4EPSS 0.003
← Prev2 / 3Next →