VYPR

Snipe It

by Snipeitapp

Source repositories

CVEs (104)

  • CVE-2021-3938MedNov 13, 2021
    risk 0.28cvss 5.4epss 0.01

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3879MedOct 19, 2021
    risk 0.28cvss 5.4epss 0.01

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2026-86767MedSep 9, 2026
    risk 0.26cvss 5.0epss 0.00

    Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset requests from all companies. Attackers can…

  • CVE-2026-86743MedSep 9, 2026
    risk 0.26cvss 5.0epss 0.00

    Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets report page or CSV export to disclose…

  • CVE-2026-55515MedJul 10, 2026
    risk 0.26cvss 5.0epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset,…

  • CVE-2026-55481MedJul 10, 2026
    risk 0.24cvss 4.8epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that…

  • CVE-2026-44831MedMay 26, 2026
    risk 0.24cvss 4.8epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1.

  • CVE-2022-3035MedAug 29, 2022
    risk 0.24cvss 4.8epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.

  • CVE-2026-86769MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with…

  • CVE-2026-86761MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to…

  • CVE-2026-86753MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create checkout requests for non-requestable asset models by…

  • CVE-2026-55479MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unassign them to directly access…

  • CVE-2026-55462MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view…

  • CVE-2026-55476MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an authenticated user to supply a victim…

  • CVE-2026-55472MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of…

  • CVE-2026-55542MedJul 8, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the…

  • CVE-2022-3173MedSep 17, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.

  • CVE-2021-4089MedDec 10, 2021
    risk 0.21cvss 4.3epss 0.01

    snipe-it is vulnerable to Improper Access Control

  • CVE-2021-3931MedNov 13, 2021
    risk 0.21cvss 4.3epss 0.00

    snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2026-86740LowSep 9, 2026
    risk 0.18cvss 3.8epss 0.00

    Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Administrators performing attachment deletions…

Page 5 of 6