Known Vulnerabilities for products from Snipeitapp
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Snipeitapp".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86738 json | Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization t... | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-86737 json | snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authen... | Not Provided | 2026-09-08 | 2026-09-10 |
| CVE-2026-86736 json | snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated ... | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-86735 json | snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fa... | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-86734 json | Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allow... | Not Provided | 2026-09-08 | 2026-09-10 |
| CVE-2026-86733 json | Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line clie... | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-55843 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission requ... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-55542 json | Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks author... | Not Provided | 2026-07-08 | 2026-07-10 |
| CVE-2026-55516 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} checks ... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55515 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes on... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55481 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related brandin... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55479 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55478 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the cal... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-55476 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-55475 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import ca... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55474 json | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route fil... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-55472 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_f... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-55469 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permis... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55466 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finf... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55464 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascri... | Not Provided | 2026-07-10 | 2026-07-13 |
Known software with vulnerabilities from Snipeitapp
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Snipeitapp | Snipe-it | 0.1.0 |