VYPR
Vendor

Snipeitapp

Products
1
CVEs
73
Across products
73
Status
Private

Products

1

Recent CVEs

73
View all 73 CVEs →
  • CVE-2026-37709CriMay 7, 2026
    risk 0.57cvss 9.8epss 0.00

    Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component

  • CVE-2024-51093HigNov 12, 2024
    risk 0.57cvss 8.7epss 0.00

    Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the…

  • CVE-2024-51094HigNov 12, 2024
    risk 0.52cvss 8.0epss 0.00

    An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. When an administrator later accesses the People Management page, exports the data as a CSV file, and opens it, the…

  • CVE-2026-44832HigMay 26, 2026
    risk 0.50cvss 8.8epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1. The API controller only strips the…

  • CVE-2025-15602HigMar 6, 2026
    risk 0.50cvss 8.8epss 0.00

    Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user…

  • CVE-2023-5511HigOct 11, 2023
    risk 0.50cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3.

  • CVE-2022-23064HigMay 2, 2022
    risk 0.50cvss 8.8epss 0.01

    In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus…

  • CVE-2021-4130HigDec 18, 2021
    risk 0.50cvss 8.8epss 0.00

    snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-3858HigOct 19, 2021
    risk 0.50cvss 8.8epss 0.01

    snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2026-54329HigJul 10, 2026
    risk 0.48cvss 8.5epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company to create accessory records…

  • CVE-2022-2997HigAug 25, 2022
    risk 0.45cvss 8.0epss 0.01

    Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.

  • CVE-2026-38533MedApr 14, 2026
    risk 0.42cvss 6.5epss 0.00

    An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.

  • CVE-2024-5685HigJun 14, 2024
    risk 0.42cvss 7.6epss 0.00

    Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.

  • CVE-2022-1155HigMar 30, 2022
    risk 0.41cvss 7.4epss 0.01

    Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.

  • CVE-2025-64027MedNov 20, 2025
    risk 0.40cvss 6.1epss 0.00

    Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an invalid CSV file is uploaded, the application returns a progress_message value that is rendered as raw HTML in the admin interface. An attacker can…

  • CVE-2021-4075HigDec 6, 2021
    risk 0.40cvss 7.2epss 0.01

    snipe-it is vulnerable to Server-Side Request Forgery (SSRF)

  • CVE-2026-48507HigJun 8, 2026
    risk 0.39cvss 7.1epss 0.00

    Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user holding only the granular `users.edit` permission to lock every admin out of the instance by editing the `activated` flag (which determines whether or not a…

  • CVE-2025-59713MedSep 19, 2025
    risk 0.37cvss 6.8epss 0.00

    Snipe-IT before 8.1.18 allows unsafe deserialization.

  • CVE-2024-48987MedOct 11, 2024
    risk 0.36cvss 6.6epss 0.01

    Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.

  • CVE-2026-48492MedJul 8, 2026
    risk 0.35cvss 6.5epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated list of all user accounts…