VYPR

Snipe-IT

by Snipe IT

Source repositories

CVEs (43)

  • CVE-2026-86742MedSep 9, 2026
    risk 0.35cvss 6.5epss 0.00

    Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. ReportsController::postAssetAcceptanceReport builds the CSV by hand (stripping commas and joining rows manually) and, unlike the six sibling exports in the same…

  • CVE-2026-48492MedJul 8, 2026
    risk 0.35cvss 6.5epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated list of all user accounts…

  • CVE-2019-25264MedFeb 3, 2026
    risk 0.35cvss 6.4epss 0.00

    Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the accessory is viewed by other users.

  • CVE-2022-44381MedDec 25, 2022
    risk 0.35cvss 5.3epss 0.01

    Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.

  • CVE-2022-44380MedDec 25, 2022
    risk 0.35cvss 5.4epss 0.00

    Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.

  • CVE-2026-86749MedSep 9, 2026
    risk 0.34cvss 6.3epss 0.00

    Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in ImageUploadRequest::handleImages(). Because Laravel's default disk mode does not throw on failure, a silently failed Storage::disk('public')->put(...) call still caused the…

  • CVE-2026-55482MedAug 19, 2026
    risk 0.34cvss 6.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing assets to be moved across company boundaries…

  • CVE-2026-86756MedSep 9, 2026
    risk 0.33cvss 6.1epss 0.00

    Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into Laravel's url.intended session key with only CR/LF characters…

  • CVE-2026-49870MedAug 19, 2026
    risk 0.31cvss 5.9epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or attempt counter, allowing an attacker with valid credentials to submit unlimited TOTP guesses against the three accepted codes created by config/google2fa.php…

  • CVE-2022-32061MedJul 7, 2022
    risk 0.31cvss 4.8epss 0.01

    An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2022-32060MedJul 7, 2022
    risk 0.31cvss 4.8epss 0.01

    An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2026-55475MedJul 10, 2026
    risk 0.30cvss 5.7epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata. This…

  • CVE-2026-48493MedJun 23, 2026
    risk 0.29cvss 5.5epss 0.00

    Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser — for example `assets.view`, `assets.create`,…

  • CVE-2026-88894MedSep 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, license and consumable checkout paths, App\Services\PredefinedKitCheckoutService never calls…

  • CVE-2026-86747MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder (ReportsController::sentAssetAcceptanceReminder) and DELETE /reports/unaccepted_assets/{acceptanceId}/delete…

  • CVE-2026-19579MedAug 11, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side…

  • CVE-2026-55478MedJul 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user with predefined-kit permissions to bind a…

  • CVE-2025-63743MedApr 13, 2026
    risk 0.28cvss 5.4epss 0.00

    Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 allows authenticated attacker with lowest privileges sufficient only to log in, to inject arbitrary JavaScript code via "Name" and "Surname" fields. The…

  • CVE-2026-55483MedAug 19, 2026
    risk 0.25cvss epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission can submit the admin permission while creating a user because store() in app/Http/Controllers/Users/UsersController.php strips superuser permission but does not…

  • CVE-2026-55481MedJul 10, 2026
    risk 0.24cvss 4.8epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that…