Snipe It
by Snipeitapp
Source repositories
CVEs (104)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-3938 | Med | 0.28 | 5.4 | 0.01 | Nov 13, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-3879 | Med | 0.28 | 5.4 | 0.01 | Oct 19, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2026-86767 | Med | 0.26 | 5.0 | 0.00 | Sep 9, 2026 | Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset requests from all companies. Attackers can… | ||
| CVE-2026-86743 | Med | 0.26 | 5.0 | 0.00 | Sep 9, 2026 | Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets report page or CSV export to disclose… | ||
| CVE-2026-55515 | Med | 0.26 | 5.0 | 0.00 | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset,… | ||
| CVE-2026-55481 | Med | 0.24 | 4.8 | 0.00 | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that… | ||
| CVE-2026-44831 | Med | 0.24 | 4.8 | 0.00 | May 26, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1. | ||
| CVE-2022-3035 | Med | 0.24 | 4.8 | 0.01 | Aug 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11. | ||
| CVE-2026-86769 | Med | 0.21 | 4.3 | 0.00 | Sep 9, 2026 | Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with… | ||
| CVE-2026-86761 | Med | 0.21 | 4.3 | 0.00 | Sep 9, 2026 | snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to… | ||
| CVE-2026-86753 | Med | 0.21 | 4.3 | 0.00 | Sep 9, 2026 | snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create checkout requests for non-requestable asset models by… | ||
| CVE-2026-55479 | Med | 0.21 | 4.3 | 0.00 | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unassign them to directly access… | ||
| CVE-2026-55462 | Med | 0.21 | 4.3 | 0.00 | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view… | ||
| CVE-2026-55476 | Med | 0.21 | 4.3 | 0.00 | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an authenticated user to supply a victim… | ||
| CVE-2026-55472 | Med | 0.21 | 4.3 | 0.00 | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of… | ||
| CVE-2026-55542 | Med | 0.21 | 4.3 | 0.00 | Jul 8, 2026 | Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the… | ||
| CVE-2022-3173 | Med | 0.21 | 4.3 | 0.01 | Sep 17, 2022 | Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10. | ||
| CVE-2021-4089 | Med | 0.21 | 4.3 | 0.01 | Dec 10, 2021 | snipe-it is vulnerable to Improper Access Control | ||
| CVE-2021-3931 | Med | 0.21 | 4.3 | 0.00 | Nov 13, 2021 | snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2026-86740 | Low | 0.18 | 3.8 | 0.00 | Sep 9, 2026 | Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Administrators performing attachment deletions… |
- risk 0.28cvss 5.4epss 0.01
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.28cvss 5.4epss 0.01
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.26cvss 5.0epss 0.00
Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset requests from all companies. Attackers can…
- risk 0.26cvss 5.0epss 0.00
Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets report page or CSV export to disclose…
- risk 0.26cvss 5.0epss 0.00
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset,…
- risk 0.24cvss 4.8epss 0.00
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that…
- risk 0.24cvss 4.8epss 0.00
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1.
- risk 0.24cvss 4.8epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.
- risk 0.21cvss 4.3epss 0.00
Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with…
- risk 0.21cvss 4.3epss 0.00
snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to…
- risk 0.21cvss 4.3epss 0.00
snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create checkout requests for non-requestable asset models by…
- risk 0.21cvss 4.3epss 0.00
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unassign them to directly access…
- risk 0.21cvss 4.3epss 0.00
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view…
- risk 0.21cvss 4.3epss 0.00
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an authenticated user to supply a victim…
- risk 0.21cvss 4.3epss 0.00
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of…
- risk 0.21cvss 4.3epss 0.00
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the…
- risk 0.21cvss 4.3epss 0.01
Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.
- risk 0.21cvss 4.3epss 0.01
snipe-it is vulnerable to Improper Access Control
- risk 0.21cvss 4.3epss 0.00
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.18cvss 3.8epss 0.00
Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Administrators performing attachment deletions…
Page 5 of 6