VulnSea

snipe/snipe-it vulnerabilities

CVEs whose affected-version data names the snipe/snipe-it package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

20 CVEsRSS

CVE-2026-55843High· 6.5
3w ago

Snipe-IT has an Improper Privilege Management issue

Snipe-IT has an Improper Privilege Management issue

Twilightsnipe · snipe/snipe-itEPSS 0.54%via GHSA
CVE-2026-55460High· 7.1
3w ago

Snipe-IT has an authorization bypass on bulk editing users

Snipe-IT has an authorization bypass on bulk editing users

Twilightsnipe · snipe/snipe-itEPSS 0.44%via GHSA
CVE-2026-55464Medium· 5.4
3w ago

Snipe-IT vulnerable to stored XSS via Markdown custom field

Snipe-IT vulnerable to stored XSS via Markdown custom field

Sunlitsnipe · snipe/snipe-itEPSS 0.29%via GHSA
CVE-2026-55472Medium· 4.3
3w ago

Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation

Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation

Sunlitsnipe · snipe/snipe-itEPSS 0.33%via GHSA
CVE-2026-55476Medium
3w ago

Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter

Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter

Sunlitsnipe · snipe/snipe-itEPSS 0.20%via GHSA
CVE-2026-55516High· 7.7
3w ago

Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update

Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update

Twilightsnipe · snipe/snipe-itEPSS 0.38%via GHSA
CVE-2026-55694High
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-…

Twilightsnipe · snipe/snipe-itEPSS 0.30%via NVD
CVE-2026-55703Medium· 4.3
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Control…

Sunlitsnipe · snipe/snipe-itEPSS 0.24%via NVD
CVE-2026-61807Medium
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-si…

Sunlitsnipe · snipe/snipe-itEPSS 0.28%via NVD
CVE-2026-49870Medium· 5.9
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or attempt counter, allowing an attacker with valid credentials to submit unlimited TOTP guesses against the three accepte…

Sunlitsnipe · snipe/snipe-itEPSS 0.31%via NVD
CVE-2026-49976Medium· 6.5
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email address of a non-admin user and then request a password reset to take over that account. …

Sunlitsnipe · snipe/snipe-itEPSS 0.34%via NVD
CVE-2026-50550Medium· 5.8
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php postTwoFactorReset(). The endpoint…

Sunlitsnipe · snipe/snipe-itEPSS 0.18%via NVD
CVE-2026-55482Medium· 6.3
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing asse…

Sunlitsnipe · snipe/snipe-itEPSS 0.19%via NVD
CVE-2026-55483Medium
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission can submit the admin permission while creating a user because store() in app/Http/Controllers/Users/UsersController.php…

Sunlitsnipe · snipe/snipe-itEPSS 0.30%via NVD
CVE-2026-55519Medium· 5.4
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in …

Sunlitsnipe · snipe/snipe-itEPSS 0.21%via NVD
CVE-2026-48492Medium
3mo ago

Snipe-IT's selectlist visibility is too permissive

Snipe-IT's selectlist visibility is too permissive

Sunlitsnipe · snipe/snipe-itEPSS 0.39%via GHSA
CVE-2026-48493Medium· 5.5
3mo ago

Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment

Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment

Sunlitsnipe · snipe/snipe-itEPSS 0.31%via GHSA
CVE-2026-48507High· 7.1
3mo ago

Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users

Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users

Twilightsnipe · snipe/snipe-itEPSS 0.24%via GHSA
CVE-2026-55542Low
3mo ago

Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL

Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL

Sunlitsnipe · snipe/snipe-itEPSS 0.28%via GHSA
CVE-2026-54329High· 8.5
3mo ago

Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection

Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection

Twilightsnipe · snipe/snipe-itEPSS 0.39%via GHSA
snipe/snipe-it vulnerabilities (CVEs) · VulnSea