snipeitapp
49 known vulnerabilities affecting snipeitapp products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-86733 | Medium | 0.3% | 7.2 | Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive dire… | |
| CVE-2026-86762 | Medium | 0.3% | 8.1 | Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the … | |
| CVE-2026-86770 | Medium | 0.3% | 8.1 | Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML au… | |
| CVE-2026-44832 | Medium | 0.3% | 8.8 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authentic… | |
| CVE-2026-86738 | Medium | 0.3% | 8.7 | Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Cust… | |
| CVE-2026-85617 | Medium | 0.3% | 8.8 | snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in … | |
| CVE-2026-86751 | Medium | 0.3% | 8.5 | Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note f… | |
| CVE-2026-85616 | Medium | 0.2% | 8.5 | Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in … | |
| CVE-2026-86741 | Medium | 0.2% | 8.5 | Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field bef… | |
| CVE-2026-48507 | Medium | 0.2% | 7.1 | Snipe-IT is an IT asset/license management system. A vulnerability in versions p… | |
| CVE-2026-86759 | Medium | 0.2% | 7.1 | Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endp… | |
| CVE-2026-86771 | Medium | 0.2% | 7.6 | Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the… | |
| CVE-2026-86754 | Medium | 0.2% | 7.3 | Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client man… | |
| CVE-2026-86750 | Medium | 0.2% | 7.7 | Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment a… | |
| CVE-2026-86745 | Low | 0.4% | 6.5 | Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds… | |
| CVE-2026-86748 | Low | 0.3% | 6.1 | Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded … | |
| CVE-2026-86734 | Low | 0.3% | 6.5 | Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST… | |
| CVE-2026-86742 | Low | 0.3% | 6.5 | Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted a… | |
| CVE-2026-19579 | Low | 0.3% | 5.4 | Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object r… | |
| CVE-2026-86746 | Low | 0.3% | 6.4 | Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire… | |
| CVE-2026-86743 | Low | 0.3% | 5.0 | Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report qu… | |
| CVE-2026-86739 | Low | 0.3% | 3.1 | Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when … | |
| CVE-2026-86761 | Low | 0.2% | 4.3 | snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in … | |
| CVE-2026-86735 | Low | 0.2% | 5.0 | snipe-it versions before 8.7.0 contain a server-side request forgery vulnerabili… | |
| CVE-2026-86758 | Low | 0.2% | 6.5 | Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate … | |
| CVE-2026-86749 | Low | 0.2% | 6.3 | Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of sto… | |
| CVE-2026-86768 | Low | 0.2% | 5.4 | Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpo… | |
| CVE-2026-86766 | Low | 0.2% | 6.5 | Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in… | |
| CVE-2026-86765 | Low | 0.2% | 6.5 | Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assig… | |
| CVE-2026-44831 | Low | 0.2% | 4.8 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with co… | |
| CVE-2026-86760 | Low | 0.2% | 5.4 | Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect auth… | |
| CVE-2026-86757 | Low | 0.2% | 6.5 | Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field va… | |
| CVE-2026-86764 | Low | 0.2% | 6.5 | Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view per… | |
| CVE-2026-86744 | Low | 0.2% | 2.2 | Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) co… | |
| CVE-2026-86740 | Low | 0.2% | 3.8 | Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in Up… | |
| CVE-2026-86756 | Low | 0.2% | 6.1 | Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML… | |
| CVE-2026-86753 | Low | 0.2% | 4.3 | snipe-it versions before 8.7.0 fail to validate the requestable flag for asset m… | |
| CVE-2026-86755 | Low | 0.2% | 5.4 | Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered … | |
| CVE-2026-86767 | Low | 0.2% | 5.0 | Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET … | |
| CVE-2026-86747 | Low | 0.2% | 5.4 | Snipe-IT is an open source IT asset management system. In versions up to and inc… | |
| CVE-2026-86752 | Low | 0.2% | 5.4 | snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asse… | |
| CVE-2026-86736 | Low | 0.2% | 4.3 | snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkou… | |
| CVE-2026-86773 | Low | 0.2% | 5.4 | Snipe-IT through version 8.6.3 fails to perform object-level authorization in th… | |
| CVE-2026-86737 | Low | 0.2% | 4.3 | snipe-it versions before 8.7.0 fail to enforce asset view authorization in the G… | |
| CVE-2026-86774 | Low | 0.2% | 6.3 | Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in … | |
| CVE-2026-44833 | Low | 0.2% | 5.9 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redir… | |
| CVE-2026-86769 | Low | 0.2% | 4.3 | Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerab… | |
| CVE-2026-86763 | Low | 0.2% | 3.5 | Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the … | |
| CVE-2026-86772 | Low | 0.1% | 5.4 | Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerabili… |