VYPR
Vendor
Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2025-15602Hig0.508.80.00Mar 6, 2026Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account, including the Super Admin account. By changing the email address of the Super Admin and triggering a password reset, an attacker can fully take over the Super Admin account, resulting in complete administrative control of the Snipe-IT instance.
CVE-2026-38533Med0.426.50.00Apr 14, 2026An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.
CVE-2025-472260.030.01May 2, 2025Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
CVE-2025-597130.000.00Sep 19, 2025Snipe-IT before 8.1.18 allows unsafe deserialization.
CVE-2025-597120.000.00Sep 19, 2025Snipe-IT before 8.1.18 allows XSS.