VYPR

Snipe-IT

by Snipe IT

Source repositories

CVEs (43)

  • CVE-2026-86769MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with…

  • CVE-2026-55542MedJul 8, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the…

  • CVE-2025-63601CriNov 5, 2025
    risk 0.00cvss 9.9epss 0.01

    Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and execute system commands.

Page 3 of 3