VYPR

Vendor CVEs

Snipeitapp

All CVEs

104 total · sorted by risk
  • CVE-2026-86756MedSep 9, 2026
    risk 0.33cvss 6.1epss 0.00

    Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into Laravel's url.intended session key with only CR/LF characters…

  • CVE-2026-86748MedSep 9, 2026
    risk 0.33cvss 6.1epss 0.00

    Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.

  • CVE-2026-55461MedJul 10, 2026
    risk 0.33cvss 6.1epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the attacker-controlled Referer header into Laravel’s intended URL session value and later uses redirect()->intended(...) when redirect_option=back is submitted,…

  • CVE-2021-4108MedDec 14, 2021
    risk 0.33cvss 6.1epss 0.01

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3863MedOct 19, 2021
    risk 0.33cvss 6.1epss 0.01

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2026-50550MedAug 19, 2026
    risk 0.31cvss 5.8epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php postTwoFactorReset(). The endpoint authorizes update access but does not…

  • CVE-2026-44833MedMay 26, 2026
    risk 0.31cvss 5.9epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1.

  • CVE-2022-32061MedJul 7, 2022
    risk 0.31cvss 4.8epss 0.01

    An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2022-32060MedJul 7, 2022
    risk 0.31cvss 4.8epss 0.01

    An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2026-55475MedJul 10, 2026
    risk 0.30cvss 5.7epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata. This…

  • CVE-2026-48493MedJun 23, 2026
    risk 0.29cvss 5.5epss 0.00

    Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser — for example `assets.view`, `assets.create`,…

  • CVE-2025-47226MedMay 2, 2025
    risk 0.29cvss 5.0epss 0.01

    Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.

  • CVE-2026-88894MedSep 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, license and consumable checkout paths, App\Services\PredefinedKitCheckoutService never calls…

  • CVE-2026-86768MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can submit POST requests to hardware, component, or consumable checkout endpoints…

  • CVE-2026-86760MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update(). The single-user edit route assigned the activated field from the request payload before evaluating the canEditAuthFields…

  • CVE-2026-86755MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission gate that Snipe-IT enforces on its own token…

  • CVE-2026-86752MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permissions could write audit log entries…

  • CVE-2026-55519MedAug 19, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in app/Http/Controllers/Api/UploadedFilesContr…

  • CVE-2026-55478MedJul 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user with predefined-kit permissions to bind a…

  • CVE-2026-55464MedJul 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea custom field that executes…

  • CVE-2025-65622MedDec 1, 2025
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.

  • CVE-2025-65621MedDec 1, 2025
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.

  • CVE-2023-5452MedOct 6, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2.

  • CVE-2022-1445MedApr 24, 2022
    risk 0.28cvss 5.4epss 0.01

    Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.

  • CVE-2022-1380MedApr 16, 2022
    risk 0.28cvss 5.4epss 0.01

    Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie.

  • CVE-2022-0622MedFeb 17, 2022
    risk 0.28cvss 5.3epss 0.01

    Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.

  • CVE-2022-0569MedFeb 14, 2022
    risk 0.28cvss 5.3epss 0.01

    Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.

  • CVE-2022-0179MedJan 12, 2022
    risk 0.28cvss 5.4epss 0.01

    snipe-it is vulnerable to Missing Authorization

  • CVE-2021-4018MedDec 1, 2021
    risk 0.28cvss 5.4epss 0.01

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3961MedNov 19, 2021
    risk 0.28cvss 5.4epss 0.01

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3938MedNov 13, 2021
    risk 0.28cvss 5.4epss 0.01

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3879MedOct 19, 2021
    risk 0.28cvss 5.4epss 0.01

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2026-86767MedSep 9, 2026
    risk 0.26cvss 5.0epss 0.00

    Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset requests from all companies. Attackers can…

  • CVE-2026-86743MedSep 9, 2026
    risk 0.26cvss 5.0epss 0.00

    Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets report page or CSV export to disclose…

  • CVE-2026-55515MedJul 10, 2026
    risk 0.26cvss 5.0epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset,…

  • CVE-2026-55481MedJul 10, 2026
    risk 0.24cvss 4.8epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that…

  • CVE-2026-44831MedMay 26, 2026
    risk 0.24cvss 4.8epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1.

  • CVE-2022-3035MedAug 29, 2022
    risk 0.24cvss 4.8epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.

  • CVE-2026-86769MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with…

  • CVE-2026-86761MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to…

  • CVE-2026-86753MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create checkout requests for non-requestable asset models by…

  • CVE-2026-55479MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unassign them to directly access…

  • CVE-2026-55462MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view…

  • CVE-2026-55476MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an authenticated user to supply a victim…

  • CVE-2026-55472MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of…

  • CVE-2026-55542MedJul 8, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the…

  • CVE-2022-3173MedSep 17, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.

  • CVE-2021-4089MedDec 10, 2021
    risk 0.21cvss 4.3epss 0.01

    snipe-it is vulnerable to Improper Access Control

  • CVE-2021-3931MedNov 13, 2021
    risk 0.21cvss 4.3epss 0.00

    snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2026-86740LowSep 9, 2026
    risk 0.18cvss 3.8epss 0.00

    Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Administrators performing attachment deletions…