Snipe It
by Snipeitapp
Source repositories
CVEs (104)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-48493 | Med | 0.29 | 5.5 | 0.00 | Jun 23, 2026 | Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser — for example `assets.view`, `assets.create`,… | ||
| CVE-2025-47226 | Med | 0.29 | 5.0 | 0.01 | May 2, 2025 | Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information. | ||
| CVE-2026-88894 | Med | 0.28 | 5.4 | 0.00 | Sep 10, 2026 | Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, license and consumable checkout paths, App\Services\PredefinedKitCheckoutService never calls… | ||
| CVE-2026-86768 | Med | 0.28 | 5.4 | 0.00 | Sep 9, 2026 | Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can submit POST requests to hardware, component, or consumable checkout endpoints… | ||
| CVE-2026-86760 | Med | 0.28 | 5.4 | 0.00 | Sep 9, 2026 | Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update(). The single-user edit route assigned the activated field from the request payload before evaluating the canEditAuthFields… | ||
| CVE-2026-86755 | Med | 0.28 | 5.4 | 0.00 | Sep 9, 2026 | Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission gate that Snipe-IT enforces on its own token… | ||
| CVE-2026-86752 | Med | 0.28 | 5.4 | 0.00 | Sep 9, 2026 | snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permissions could write audit log entries… | ||
| CVE-2026-55519 | Med | 0.28 | 5.4 | 0.00 | Aug 19, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in app/Http/Controllers/Api/UploadedFilesContr… | ||
| CVE-2026-55478 | Med | 0.28 | 5.4 | 0.00 | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user with predefined-kit permissions to bind a… | ||
| CVE-2026-55464 | Med | 0.28 | 5.4 | 0.00 | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea custom field that executes… | ||
| CVE-2025-65622 | Med | 0.28 | 5.4 | 0.00 | Dec 1, 2025 | Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session. | ||
| CVE-2025-65621 | Med | 0.28 | 5.4 | 0.00 | Dec 1, 2025 | Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation. | ||
| CVE-2023-5452 | Med | 0.28 | 5.4 | 0.01 | Oct 6, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2. | ||
| CVE-2022-1445 | Med | 0.28 | 5.4 | 0.01 | Apr 24, 2022 | Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie. | ||
| CVE-2022-1380 | Med | 0.28 | 5.4 | 0.01 | Apr 16, 2022 | Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie. | ||
| CVE-2022-0622 | Med | 0.28 | 5.3 | 0.01 | Feb 17, 2022 | Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11. | ||
| CVE-2022-0569 | Med | 0.28 | 5.3 | 0.01 | Feb 14, 2022 | Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9. | ||
| CVE-2022-0179 | Med | 0.28 | 5.4 | 0.01 | Jan 12, 2022 | snipe-it is vulnerable to Missing Authorization | ||
| CVE-2021-4018 | Med | 0.28 | 5.4 | 0.01 | Dec 1, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-3961 | Med | 0.28 | 5.4 | 0.01 | Nov 19, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
- risk 0.29cvss 5.5epss 0.00
Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser — for example `assets.view`, `assets.create`,…
- risk 0.29cvss 5.0epss 0.01
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
- risk 0.28cvss 5.4epss 0.00
Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, license and consumable checkout paths, App\Services\PredefinedKitCheckoutService never calls…
- risk 0.28cvss 5.4epss 0.00
Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can submit POST requests to hardware, component, or consumable checkout endpoints…
- risk 0.28cvss 5.4epss 0.00
Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update(). The single-user edit route assigned the activated field from the request payload before evaluating the canEditAuthFields…
- risk 0.28cvss 5.4epss 0.00
Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission gate that Snipe-IT enforces on its own token…
- risk 0.28cvss 5.4epss 0.00
snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permissions could write audit log entries…
- risk 0.28cvss 5.4epss 0.00
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in app/Http/Controllers/Api/UploadedFilesContr…
- risk 0.28cvss 5.4epss 0.00
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user with predefined-kit permissions to bind a…
- risk 0.28cvss 5.4epss 0.00
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea custom field that executes…
- risk 0.28cvss 5.4epss 0.00
Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.
- risk 0.28cvss 5.4epss 0.00
Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2.
- risk 0.28cvss 5.4epss 0.01
Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.
- risk 0.28cvss 5.4epss 0.01
Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie.
- risk 0.28cvss 5.3epss 0.01
Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.
- risk 0.28cvss 5.3epss 0.01
Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.
- risk 0.28cvss 5.4epss 0.01
snipe-it is vulnerable to Missing Authorization
- risk 0.28cvss 5.4epss 0.01
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.28cvss 5.4epss 0.01
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Page 4 of 6