VendorsSnipeitappsnipe-itany version
Vulnerabilities

Snipeitapp Snipe-IT any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

109CVEs
CVE-2026-86772
Snipe-IT 8.6.3 Stored XSS via Department Names
Published 2026-09-09 · Analyzed
5.4EPSS 0.003
CVE-2026-86773
Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints
Published 2026-09-09 · Analyzed
5.4EPSS 0.003
CVE-2026-86747
snipe-it before 8.7.0 Authorization Bypass via Pivot-Only User
Published 2026-09-09 · Analyzed
5.4EPSS 0.003
CVE-2026-86752
snipe-it before 8.7.0 Authorization Bypass via Asset Audit Endpoints
Published 2026-09-09 · Analyzed
5.4EPSS 0.002
CVE-2025-65622
Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.
Published 2025-12-01 · Modified
5.4EPSS 0.002
CVE-2025-65621
Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.
Published 2025-12-01 · Modified
5.4EPSS 0.002
CVE-2022-0569
Observable Discrepancy in snipe/snipe-it
Published 2022-02-12 · Modified
5.3EPSS 0.010
CVE-2022-0622
Generation of Error Message Containing Sensitive Information in snipe/snipe-it
Published 2022-02-17 · Modified
5.3EPSS 0.010
CVE-2022-44381
Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.
Published 2022-12-25 · Modified
5.3EPSS 0.006
CVE-2026-86761
snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints
Published 2026-09-09 · Analyzed
5.3EPSS 0.004
CVE-2026-55476
Snipe-IT: Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter
Published 2026-07-10 · Analyzed
5.3EPSS 0.003
CVE-2026-86767
Snipe-IT before 8.7.0 Cross-Company Read via requested-assets
Published 2026-09-09 · Analyzed
5.3EPSS 0.003
CVE-2026-55479
Snipe-IT: Incorrect permission for legacy license checkin API
Published 2026-07-10 · Analyzed
5.3EPSS 0.003
CVE-2026-86736
snipe-it before 8.7.0 Checkout Request Counter Integrity Failure
Published 2026-09-08 · Analyzed
5.3EPSS 0.003
CVE-2026-86743
Snipe-IT before 8.7.0 Authorization Bypass via Asset Acceptance Report
Published 2026-09-09 · Analyzed
5.3EPSS 0.003
CVE-2026-86737
snipe-it before 8.7.0 Missing Authorization via barcode endpoint
Published 2026-09-08 · Analyzed
5.3EPSS 0.003
CVE-2026-86753
snipe-it before 8.7.0 Business Logic Bypass via asset_model endpoint
Published 2026-09-09 · Analyzed
5.3EPSS 0.003
CVE-2026-86769
Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout
Published 2026-09-09 · Analyzed
5.3EPSS 0.003
CVE-2026-86740
Snipe-IT before 8.7.0 Attachment Deletion Reports Success While File Remains
Published 2026-09-09 · Analyzed
5.1EPSS 0.003
CVE-2026-86763
snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer
Published 2026-09-09 · Analyzed
5.1EPSS 0.003
CVE-2025-47226
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
Published 2025-05-02 · Analyzed
5.01 PoCEPSS 0.012
CVE-2026-55515
Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint
Published 2026-07-10 · Analyzed
5.0EPSS 0.003
CVE-2022-3173
Improper Authentication in snipe/snipe-it
Published 2022-09-17 · Modified
4.3EPSS 0.009
CVE-2021-4089
Improper Access Control in snipe/snipe-it
Published 2021-12-10 · Modified
4.3EPSS 0.007
CVE-2021-3931
Cross-Site Request Forgery (CSRF) in snipe/snipe-it
Published 2021-11-13 · Modified
4.3EPSS 0.004
CVE-2026-55462
Snipe-IT: Authorization bypass on print inventory page
Published 2026-07-10 · Analyzed
4.3EPSS 0.003
CVE-2026-55472
Snipe-IT: API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
Published 2026-07-10 · Analyzed
4.3EPSS 0.003
CVE-2026-55542
Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL
Published 2026-07-08 · Analyzed
4.3EPSS 0.003
CVE-2026-86744
snipe-it before 8.7.0 Race Condition in Asset Checkout
Published 2026-09-09 · Analyzed
2.2EPSS 0.003
← Prev3 / 3