VYPR

Snipe It

by Snipeitapp

Source repositories

CVEs (104)

  • CVE-2026-48493MedJun 23, 2026
    risk 0.29cvss 5.5epss 0.00

    Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser — for example `assets.view`, `assets.create`,…

  • CVE-2025-47226MedMay 2, 2025
    risk 0.29cvss 5.0epss 0.01

    Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.

  • CVE-2026-88894MedSep 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, license and consumable checkout paths, App\Services\PredefinedKitCheckoutService never calls…

  • CVE-2026-86768MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can submit POST requests to hardware, component, or consumable checkout endpoints…

  • CVE-2026-86760MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update(). The single-user edit route assigned the activated field from the request payload before evaluating the canEditAuthFields…

  • CVE-2026-86755MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission gate that Snipe-IT enforces on its own token…

  • CVE-2026-86752MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permissions could write audit log entries…

  • CVE-2026-55519MedAug 19, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in app/Http/Controllers/Api/UploadedFilesContr…

  • CVE-2026-55478MedJul 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user with predefined-kit permissions to bind a…

  • CVE-2026-55464MedJul 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea custom field that executes…

  • CVE-2025-65622MedDec 1, 2025
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.

  • CVE-2025-65621MedDec 1, 2025
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.

  • CVE-2023-5452MedOct 6, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2.

  • CVE-2022-1445MedApr 24, 2022
    risk 0.28cvss 5.4epss 0.01

    Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.

  • CVE-2022-1380MedApr 16, 2022
    risk 0.28cvss 5.4epss 0.01

    Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie.

  • CVE-2022-0622MedFeb 17, 2022
    risk 0.28cvss 5.3epss 0.01

    Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.

  • CVE-2022-0569MedFeb 14, 2022
    risk 0.28cvss 5.3epss 0.01

    Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.

  • CVE-2022-0179MedJan 12, 2022
    risk 0.28cvss 5.4epss 0.01

    snipe-it is vulnerable to Missing Authorization

  • CVE-2021-4018MedDec 1, 2021
    risk 0.28cvss 5.4epss 0.01

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3961MedNov 19, 2021
    risk 0.28cvss 5.4epss 0.01

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Page 4 of 6