Known Vulnerabilities for products from Snipeitapp
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Snipeitapp".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-55843 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission requ... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-55542 json | Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks author... | Not Provided | 2026-07-08 | 2026-07-10 |
| CVE-2026-55516 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} checks ... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55515 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes on... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55481 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related brandin... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55479 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55478 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the cal... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-55476 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-55475 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import ca... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55474 json | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route fil... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-55472 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_f... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-55469 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permis... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55466 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finf... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55464 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascri... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-55462 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize onl... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55461 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the attac... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55460 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-55452 json | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent heade... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-54329 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request param... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-48507 json | Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user holding... | Not Provided | 2026-06-08 | 2026-07-23 |
Known software with vulnerabilities from Snipeitapp
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Snipeitapp | Snipe-it | 0.1.0 |