VYPR

Snipe It

by Snipeitapp

Source repositories

CVEs (104)

  • CVE-2026-48492MedJul 8, 2026
    risk 0.35cvss 6.5epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated list of all user accounts…

  • CVE-2025-59712MedSep 19, 2025
    risk 0.35cvss 6.4epss 0.00

    Snipe-IT before 8.1.18 allows XSS.

  • CVE-2022-44381MedDec 25, 2022
    risk 0.35cvss 5.3epss 0.01

    Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.

  • CVE-2022-44380MedDec 25, 2022
    risk 0.35cvss 5.4epss 0.00

    Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.

  • CVE-2022-1511MedApr 28, 2022
    risk 0.35cvss 6.5epss 0.01

    Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.

  • CVE-2022-0579MedFeb 14, 2022
    risk 0.35cvss 6.5epss 0.01

    Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.

  • CVE-2026-86774MedSep 9, 2026
    risk 0.34cvss 6.3epss 0.00

    Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset Model records without the required…

  • CVE-2026-55482MedAug 19, 2026
    risk 0.34cvss 6.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing assets to be moved across company boundaries…

  • CVE-2022-0611MedFeb 16, 2022
    risk 0.34cvss 6.3epss 0.01

    Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.

  • CVE-2022-0178MedJan 13, 2022
    risk 0.34cvss 6.3epss 0.01

    Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.

  • CVE-2026-86756MedSep 9, 2026
    risk 0.33cvss 6.1epss 0.00

    Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into Laravel's url.intended session key with only CR/LF characters…

  • CVE-2026-86748MedSep 9, 2026
    risk 0.33cvss 6.1epss 0.00

    Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.

  • CVE-2026-55461MedJul 10, 2026
    risk 0.33cvss 6.1epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the attacker-controlled Referer header into Laravel’s intended URL session value and later uses redirect()->intended(...) when redirect_option=back is submitted,…

  • CVE-2021-4108MedDec 14, 2021
    risk 0.33cvss 6.1epss 0.01

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3863MedOct 19, 2021
    risk 0.33cvss 6.1epss 0.01

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2026-50550MedAug 19, 2026
    risk 0.31cvss 5.8epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php postTwoFactorReset(). The endpoint authorizes update access but does not…

  • CVE-2026-44833MedMay 26, 2026
    risk 0.31cvss 5.9epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1.

  • CVE-2022-32061MedJul 7, 2022
    risk 0.31cvss 4.8epss 0.01

    An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2022-32060MedJul 7, 2022
    risk 0.31cvss 4.8epss 0.01

    An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2026-55475MedJul 10, 2026
    risk 0.30cvss 5.7epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata. This…

Page 3 of 6