Known Vulnerabilities for Assets by Silverstripe
Listed below are 2 of the newest known vulnerabilities associated with "Assets" by "Silverstripe".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-89257 json | AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.ph... | Not Provided | 2026-09-11 | 2026-09-15 |
| CVE-2026-88894 json | Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkou... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-87814 json | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to e... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-87813 json | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filena... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-86774 json | Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cas... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-86772 json | Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink(... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-86767 json | Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multip... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-86765 json | Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset updat... | Not Provided | 2026-09-09 | 2026-09-14 |
| CVE-2026-86764 json | Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /ap... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-86762 json | Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php... | Not Provided | 2026-09-09 | 2026-09-10 |