← All vendors

snipeitapp

49 known vulnerabilities affecting snipeitapp products.

Products

snipe-it 49

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-86733 Medium 0.3% 7.2 Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive dire…
CVE-2026-86762 Medium 0.3% 8.1 Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the …
CVE-2026-86770 Medium 0.3% 8.1 Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML au…
CVE-2026-44832 Medium 0.3% 8.8 Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authentic…
CVE-2026-86738 Medium 0.3% 8.7 Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Cust…
CVE-2026-85617 Medium 0.3% 8.8 snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in …
CVE-2026-86751 Medium 0.3% 8.5 Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note f…
CVE-2026-85616 Medium 0.2% 8.5 Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in …
CVE-2026-86741 Medium 0.2% 8.5 Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field bef…
CVE-2026-48507 Medium 0.2% 7.1 Snipe-IT is an IT asset/license management system. A vulnerability in versions p…
CVE-2026-86759 Medium 0.2% 7.1 Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endp…
CVE-2026-86771 Medium 0.2% 7.6 Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the…
CVE-2026-86754 Medium 0.2% 7.3 Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client man…
CVE-2026-86750 Medium 0.2% 7.7 Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment a…
CVE-2026-86745 Low 0.4% 6.5 Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds…
CVE-2026-86748 Low 0.3% 6.1 Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded …
CVE-2026-86734 Low 0.3% 6.5 Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST…
CVE-2026-86742 Low 0.3% 6.5 Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted a…
CVE-2026-19579 Low 0.3% 5.4 Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object r…
CVE-2026-86746 Low 0.3% 6.4 Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire…
CVE-2026-86743 Low 0.3% 5.0 Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report qu…
CVE-2026-86739 Low 0.3% 3.1 Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when …
CVE-2026-86761 Low 0.2% 4.3 snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in …
CVE-2026-86735 Low 0.2% 5.0 snipe-it versions before 8.7.0 contain a server-side request forgery vulnerabili…
CVE-2026-86758 Low 0.2% 6.5 Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate …
CVE-2026-86749 Low 0.2% 6.3 Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of sto…
CVE-2026-86768 Low 0.2% 5.4 Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpo…
CVE-2026-86766 Low 0.2% 6.5 Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in…
CVE-2026-86765 Low 0.2% 6.5 Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assig…
CVE-2026-44831 Low 0.2% 4.8 Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with co…
CVE-2026-86760 Low 0.2% 5.4 Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect auth…
CVE-2026-86757 Low 0.2% 6.5 Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field va…
CVE-2026-86764 Low 0.2% 6.5 Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view per…
CVE-2026-86744 Low 0.2% 2.2 Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) co…
CVE-2026-86740 Low 0.2% 3.8 Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in Up…
CVE-2026-86756 Low 0.2% 6.1 Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML…
CVE-2026-86753 Low 0.2% 4.3 snipe-it versions before 8.7.0 fail to validate the requestable flag for asset m…
CVE-2026-86755 Low 0.2% 5.4 Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered …
CVE-2026-86767 Low 0.2% 5.0 Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET …
CVE-2026-86747 Low 0.2% 5.4 Snipe-IT is an open source IT asset management system. In versions up to and inc…
CVE-2026-86752 Low 0.2% 5.4 snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asse…
CVE-2026-86736 Low 0.2% 4.3 snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkou…
CVE-2026-86773 Low 0.2% 5.4 Snipe-IT through version 8.6.3 fails to perform object-level authorization in th…
CVE-2026-86737 Low 0.2% 4.3 snipe-it versions before 8.7.0 fail to enforce asset view authorization in the G…
CVE-2026-86774 Low 0.2% 6.3 Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in …
CVE-2026-44833 Low 0.2% 5.9 Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redir…
CVE-2026-86769 Low 0.2% 4.3 Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerab…
CVE-2026-86763 Low 0.2% 3.5 Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the …
CVE-2026-86772 Low 0.1% 5.4 Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerabili…