VYPR
Vendor

Grokability

Products
1
CVEs
72
Across products
72
Status
Private

Products

1

Recent CVEs

72
View all 72 CVEs →
  • CVE-2026-37709CriMay 7, 2026
    risk 0.57cvss 9.8epss 0.01

    Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component

  • CVE-2026-63498HigSep 24, 2026
    risk 0.50cvss 8.7epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments and request them with the inline=true…

  • CVE-2026-86738HigSep 8, 2026
    risk 0.50cvss 8.7epss 0.00

    Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to…

  • CVE-2026-85617HigSep 4, 2026
    risk 0.50cvss 8.8epss 0.00

    snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. Attackers can include unauthorized user IDs in bulk delete requests to bypass…

  • CVE-2026-55466HigJul 10, 2026
    risk 0.50cvss 8.7epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and UploadedFilesController serves attachments inline without using StorageHelper::allowSafeInline(), allowing a low-privilege…

  • CVE-2026-44832HigMay 26, 2026
    risk 0.50cvss 8.8epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1. The API controller only strips the…

  • CVE-2026-63493HigSep 24, 2026
    risk 0.49cvss —epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's second-factor challenge because CheckForTwoFactor is enforced…

  • CVE-2026-86751HigSep 9, 2026
    risk 0.48cvss 8.5epss 0.00

    Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image syntax in checkout acceptance notes that survive HTML…

  • CVE-2026-86741HigSep 9, 2026
    risk 0.48cvss 8.5epss 0.00

    Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it in checkout confirmation emails. Attackers with low-privilege permissions can inject markdown image syntax or raw HTML img tags pointing to local files or remote URLs, which the mail…

  • CVE-2026-85616HigSep 4, 2026
    risk 0.48cvss 8.5epss 0.00

    Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acceptance IDs and soft-delete or trigger…

  • CVE-2026-54329HigJul 10, 2026
    risk 0.48cvss 8.5epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company to create accessory records…

  • CVE-2026-62368HigSep 24, 2026
    risk 0.46cvss 8.1epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-table header title. When another user opens…

  • CVE-2026-86771HigSep 9, 2026
    risk 0.42cvss 7.6epss 0.00

    Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function. Attackers can craft a malicious employee_num value containing an img tag…

  • CVE-2026-55643HigAug 19, 2026
    risk 0.42cvss —epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserHasAccess. The /api/v1/users and…

  • CVE-2026-86754HigSep 9, 2026
    risk 0.40cvss 7.3epss 0.00

    Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs. Attackers can trick administrators into approving consent screens, then exchange…

  • CVE-2026-86733HigSep 8, 2026
    risk 0.40cvss 7.2epss 0.01

    Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands such as `\!` as local shell commands. An…

  • CVE-2026-55452HigJul 10, 2026
    risk 0.40cvss 7.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Activity Report CSV without formula escaping, allowing a low-privileged…

  • CVE-2026-86759HigSep 9, 2026
    risk 0.39cvss 7.1epss 0.00

    Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail…

  • CVE-2026-55694HigAug 19, 2026
    risk 0.39cvss —epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-eula-file/{filename}. The primary…

  • CVE-2026-55460HigJul 10, 2026
    risk 0.39cvss 7.1epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.delete can directly POST to /users/bulksave with delete_user=1 because BulkUsersController::destroy() authorizes only update,…