cbcvebase.

Snipe Snipe-It vulnerabilities

78 known vulnerabilities affecting snipe/snipe-it.

Total CVEs
78
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH20MEDIUM53LOW4

Vulnerabilities

Page 4 of 4
CVE-2021-4018P4MEDIUM≥ 0, < 5.3.32021-12-03
CVE-2021-4018 [MEDIUM] CWE-79 snipe-it is vulnerable to Cross-site Scripting snipe-it is vulnerable to Cross-site Scripting snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
ghsaosv
CVE-2021-3938P4LOW≥ 0, < 5.4.02021-11-15
CVE-2021-3938 [LOW] CWE-79 snipe-it is vulnerable to Cross-site Scripting snipe-it is vulnerable to Cross-site Scripting snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
ghsaosv
CVE-2022-44380P4MEDIUM≥ 0, < 6.0.142022-12-25
CVE-2022-44380 [MEDIUM] CWE-79 Snipe-IT vulnerable to Cross Site Scripting for View Assigned Assets Snipe-IT vulnerable to Cross Site Scripting for View Assigned Assets Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.
ghsaosv
CVE-2026-55462P4MEDIUM≥ 0, < 8.6.12026-08-28
CVE-2026-55462 [MEDIUM] CWE-863 Snipe-IT has an authorization bypass on print inventory page Snipe-IT has an authorization bypass on print inventory page ### Impact An authenticated user with only `users.view` can open another user's detail page and see assigned license, accessory, and consumable data even though the same account is denied direct access to the Licenses, Accessories, and Consumables modules. The leaked data includes software license names, purchase order/order values, accessory
ghsa
CVE-2026-55542P4LOW≥ 0, < 8.5.12026-06-23
CVE-2026-55542 [LOW] CWE-862 Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL ### Impact Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the S3 branch returns before the `authorize()` call used by the local-file branch. ## Key evide
ghsa
CVE-2026-55481P4MEDIUM≥ 0, < 8.6.22026-08-28
CVE-2026-55481 [MEDIUM] CWE-79 Snipe-IT has CSS Injection via `header_color` Setting Snipe-IT has CSS Injection via `header_color` Setting ### Impact Because `default.blade.php` is the base layout loaded on every authenticated page, all active user sessions are affected immediately upon the next page load after the payload is saved. An attacker who has compromised an admin account (or who is a malicious insider) can use this to silently exfiltrate session tokens from all other users, including
ghsa
CVE-2022-0622P4MEDIUM≥ 0, < 5.3.112022-02-18
CVE-2022-0622 [MEDIUM] CWE-209 Generation of Error Message Containing Sensitive Information in Snipe-IT Generation of Error Message Containing Sensitive Information in Snipe-IT Snipe-IT prior to version 5.3.11 is vulnerable to Generation of Error Message Containing Sensitive Information.
ghsaosv
CVE-2022-3173P4MEDIUM≥ 0, < 6.0.102022-09-18
CVE-2022-3173 [MEDIUM] CWE-287 Snipe-IT vulnerable to Improper Authentication Snipe-IT vulnerable to Improper Authentication Snipe-IT prior to 6.0.10 is vulnerable to Improper Authentication. A user without the `View and Modify License Files` permission may access files uploaded to licenses as long as they have the `View` permission for licenses.
ghsaosv
CVE-2026-55472P4MEDIUM≥ 0, < 8.6.22026-08-28
CVE-2026-55472 [MEDIUM] CWE-863 Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation ### Impact When Full Multiple Companies Support and scope_locations_fmcs are both enabled, the API endpoint for creating locations can still create a child location under a parent location from a different company. The code detects the invalid parent/child company mismatch, but it appears n
ghsa
CVE-2026-55703P4MEDIUM≥ 0, < 8.6.32026-08-19
CVE-2026-55703 [MEDIUM] CWE-862 Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET ### Impact Any activated account in a company can read every maintenance record for that company (asset tag, supplier, purchase cost, free-text notes, dates) without holding any asset or maintenance permission. ## Summary `MaintenancesController::show()` renders a maintenance record without any authorization check. Ev
ghsa
CVE-2026-55476P4MEDIUM≥ 0, < 8.6.02026-08-28
CVE-2026-55476 [MEDIUM] CWE-862 Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter ### Impact The route POST `/account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?}` accepts `cancel_by_admin` as a plain URL path segment with no authorization check. Any authenticated user regardless of permissions can set this parameter to a
ghsa
CVE-2026-55479P4MEDIUM≥ 0, < 8.6.22026-08-28
CVE-2026-55479 [MEDIUM] CWE-863 Snipe-IT has incorrect permission for legacy license checkin API Snipe-IT has incorrect permission for legacy license checkin API ### Impact The legacy single-seat license checkin flow authorizes the action with the `checkout` permission instead of the `checkin` permission. Because of this, a user who is allowed to assign licenses but not unassign them can still directly access the old checkin endpoint and reclaim a license seat that is currently assigned to anot
ghsa
CVE-2022-3035P4MEDIUM≥ 0, < 6.0.112022-08-30
CVE-2022-3035 [MEDIUM] CWE-79 snipe-it vulnerable to cross-site scripting (XSS) snipe-it vulnerable to cross-site scripting (XSS) Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.
ghsaosv
CVE-2022-0569P4MEDIUM≥ 0, < 5.3.102022-02-15
CVE-2022-0569 [MEDIUM] CWE-200 Exposure of Sensitive Information in snipe/snipe-it Exposure of Sensitive Information in snipe/snipe-it Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.10.
ghsaosv
CVE-2021-3931P4MEDIUM≥ 0, ≤ 5.3.12021-11-15
CVE-2021-3931 [MEDIUM] CWE-352 snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) snipe-it is vulnerable to Cross-Site Request Forgery (CSRF).
ghsaosv
CVE-2021-4089MEDIUM≥ 0, < 5.3.42021-12-16
CVE-2021-4089 [MEDIUM] CWE-284 snipe-it is vulnerable to Improper Access Control snipe-it is vulnerable to Improper Access Control snipe-it prior to version 5.3.4 is vulnerable to Improper Access Control. Regular users with `DENY` set to all models permissions can still view model information via the /models/{id}/clone endpoint due to no authorize('view') permission being set.
ghsaosv
CVE-2022-0179MEDIUM≥ 0, < 5.3.72022-01-21
CVE-2022-0179 [MEDIUM] CWE-276 Incorrect Default Permissions and Improper Access Control in snipe-it Incorrect Default Permissions and Improper Access Control in snipe-it snipe-it is vulnerable to Improper Access Control/Incorrect Default Permissions.
ghsaosv
CVE-2025-59712MEDIUM≥ 0, < 8.1.182025-09-19
CVE-2025-59712 [MEDIUM] CWE-79 Snipe-IT allows XSS Snipe-IT allows XSS Snipe-IT before 8.1.18 allows XSS.
ghsaosv
Snipe Snipe-It vulnerabilities | cvebase