VYPR

Packagist (Composer) package

snipe/snipe-it

pkg:composer/snipe/snipe-it

Vulnerabilities (50)

  • CVE-2026-61807MedAug 19, 2026
    affected < 8.6.2fixed 8.6.2

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-side code reads the browser-decoded countId,

  • CVE-2026-55703MedAug 19, 2026
    affected < 8.6.3fixed 8.6.3

    Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Controllers/MaintenancesController.php show() rend

  • CVE-2026-55694HigAug 19, 2026
    affected < 8.6.3fixed 8.6.3

    Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-eula-file/{filename}. The primary /stored-e

  • CVE-2026-55643HigAug 19, 2026
    affected < 8.6.3fixed 8.6.3

    Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserHasAccess. The /api/v1/users and /api/v1/u

  • CVE-2026-44833MedMay 26, 2026
    affected < 8.4.1fixed 8.4.1

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1.

  • CVE-2026-44832HigMay 26, 2026
    affected < 8.4.1fixed 8.4.1

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1. The API controller only strips the supe

  • CVE-2026-44831MedMay 26, 2026
    affected < 8.4.1fixed 8.4.1

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1.

  • CVE-2026-37709CriMay 7, 2026
    affected < 8.4.1fixed 8.4.1

    Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component

  • CVE-2025-15602HigMar 6, 2026
    affected < 8.3.7fixed 8.3.7

    Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account,

  • CVE-2025-65622MedDec 1, 2025
    affected < 8.3.4fixed 8.3.4

    Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.

  • CVE-2025-65621MedDec 1, 2025
    affected < 8.3.4fixed 8.3.4

    Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.

  • CVE-2025-64027MedNov 20, 2025
    affected <= 8.3.4

    Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an invalid CSV file is uploaded, the application returns a progress_message value that is rendered as raw HTML in the admin interface. An attacker can inte

  • CVE-2025-59713MedSep 19, 2025
    affected < 8.1.18fixed 8.1.18

    Snipe-IT before 8.1.18 allows unsafe deserialization.

  • CVE-2025-59712MedSep 19, 2025
    affected < 8.1.18fixed 8.1.18

    Snipe-IT before 8.1.18 allows XSS.

  • CVE-2025-47226MedMay 2, 2025
    affected < 8.1.0fixed 8.1.0

    Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.

  • CVE-2024-51093HigNov 12, 2024
    affected <= 7.0.13

    Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the Snipe-I

  • CVE-2024-48987MedOct 11, 2024
    affected < 7.0.10fixed 7.0.10

    Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.

  • CVE-2024-5685HigJun 14, 2024
    affected < 6.4.2fixed 6.4.2

    Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.

  • CVE-2023-5511HigOct 11, 2023
    affected < 6.2.3fixed 6.2.3

    Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3.

  • CVE-2023-5452MedOct 6, 2023
    affected < 6.2.2fixed 6.2.2

    Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2.

Page 1 of 3