VYPR

Snipe It

by Snipeitapp

Source repositories

CVEs (104)

  • CVE-2026-86739LowSep 9, 2026
    risk 0.13cvss 3.1epss 0.00

    Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when writing the signature PNG and the generated acceptance PDF in Account\AcceptanceController::store(). On filesystem drivers that return false instead of throwing on a write failure (for example the…

  • CVE-2026-86744LowSep 9, 2026
    risk 0.07cvss 2.2epss 0.00

    Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths. Api\AssetsController::checkout() and Assets\AssetCheckoutController::store() call Asset::availableForCheckout() outside the mutation path and then…

  • CVE-2025-63601CriNov 5, 2025
    risk 0.00cvss 9.9epss 0.01

    Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and execute system commands.

  • CVE-2019-10118MedMar 27, 2019
    risk 0.00cvss 6.1epss 0.01

    Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta values and the user's last name in the API.

Page 6 of 6