cbcvebase.

Snipeitapp Snipe-It vulnerabilities

74 known vulnerabilities affecting snipeitapp/snipe-it.

Total CVEs
74
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH22MEDIUM49LOW1

Vulnerabilities

Page 4 of 4
CVE-2022-44380P4MEDIUMCVSS 5.4fixed in 6.0.142022-12-25
CVE-2022-44380 [MEDIUM] CWE-79 CVE-2022-44380: Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets. Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.
nvd
CVE-2026-55481P4MEDIUMCVSS 4.8fixed in 8.6.22026-07-10
CVE-2026-55481 [MEDIUM] CWE-79 CVE-2026-55481: Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_ Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that affects authenticated users on subsequent page loads when Content Securit
nvd
CVE-2026-55462P4MEDIUMCVSS 4.3fixed in 8.6.22026-07-10
CVE-2026-55462 [MEDIUM] CWE-863 CVE-2026-55462: Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and print Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view to see inventory and cost/order metadata from modules that direct permi
nvd
CVE-2026-55542P4MEDIUMCVSS 4.3fixed in 8.6.02026-07-08
CVE-2026-55542 [MEDIUM] CWE-862 CVE-2026-55542: Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature ima Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the S3 branch returns before the `authorize()` call used by the local-file b
nvd
CVE-2026-86736P4MEDIUMCVSS 4.3fixed in 8.7.02026-09-08
CVE-2026-86736 [MEDIUM] CWE-682 CVE-2026-86736: snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling t snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel endpoints without active requests to drive the counter negative, or sub
nvd
CVE-2022-0622P4MEDIUMCVSS 5.3≤ 5.3.10v6.0.02022-02-17
CVE-2022-0622 [MEDIUM] CWE-209 CVE-2022-0622: Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5. Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.
nvd
CVE-2022-3173P4MEDIUMCVSS 4.3fixed in 6.0.102022-09-17
CVE-2022-3173 [MEDIUM] CWE-287 CVE-2022-3173: Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10. Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.
nvd
CVE-2026-55472P4MEDIUMCVSS 4.3fixed in 8.6.22026-07-10
CVE-2026-55472 [MEDIUM] CWE-863 CVE-2026-55472: Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Supp Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of a child location under a parent location from a different company. This
nvd
CVE-2026-55476P4MEDIUMCVSS 4.3fixed in 8.6.02026-07-10
CVE-2026-55476 [MEDIUM] CWE-862 CVE-2026-55476: Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/ Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an authenticated user to supply a victim user ID and silently cancel that user’s pending asset requests. This issue
nvd
CVE-2026-55479P4MEDIUMCVSS 4.3fixed in 8.6.22026-07-10
CVE-2026-55479 [MEDIUM] CWE-863 CVE-2026-55479: Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license ch Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unassign them to directly access the old checkin endpoint and reclaim a license seat assigned to another u
nvd
CVE-2026-86737P4MEDIUMCVSS 4.3fixed in 8.7.02026-09-08
CVE-2026-86737 [MEDIUM] CWE-862 CVE-2026-86737: snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset} snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including soft-deleted and cross-company assets.
nvd
CVE-2022-3035P4MEDIUMCVSS 4.8fixed in 6.0.112022-08-29
CVE-2022-3035 [MEDIUM] CWE-79 CVE-2022-3035: Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11. Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.
nvd
CVE-2022-0569P4MEDIUMCVSS 4.3fixed in 5.3.92022-02-14
CVE-2022-0569 [MEDIUM] CWE-203 CVE-2022-0569: Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9. Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.
nvd
CVE-2021-3931P4MEDIUMCVSS 4.3≤ 5.3.12021-11-13
CVE-2021-3931 [MEDIUM] CWE-352 CVE-2021-3931: snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
nvd
Snipeitapp Snipe-It vulnerabilities | cvebase