Product
snipeitapp snipe it
49 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-44833
CVE-2026-44832
CVE-2026-44831
CVE-2026-37709
CVE-2026-38533
CVE-2025-15602
CVE-2025-65622
CVE-2025-65621
CVE-2025-64027
CVE-2025-63601
CVE-2025-59713
CVE-2025-59712
CVE-2025-47226
CVE-2024-51094
CVE-2024-51093
CVE-2024-48987
CVE-2024-5685
CVE-2023-5511
CVE-2023-5452
CVE-2022-44381
CVE-2022-44380
CVE-2022-3173
CVE-2022-3035
CVE-2022-2997
CVE-2022-32061
CVE-2022-32060
CVE-2022-23064
CVE-2022-1511
CVE-2022-1445
CVE-2022-1380
CVE-2022-1155
CVE-2022-0622
CVE-2022-0611
CVE-2022-0579
CVE-2022-0569
CVE-2022-0178
CVE-2022-0179
CVE-2021-4130
CVE-2021-4108
CVE-2021-4089
CVE-2021-4075
CVE-2021-4018
CVE-2021-3961
CVE-2021-3938
CVE-2021-3931
CVE-2021-3879
CVE-2021-3863
CVE-2021-3858
CVE-2019-10118
< 8.4.1
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to
< 8.4.1
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can esca
< 8.4.1
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unesca
< 8.4.1
Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a
all versions
An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with
< 8.3.7
Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected
< 8.3.4
Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject
< 8.3.4
Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an adm
all versions
Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an in
< 8.3.3
Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a mal
< 8.1.18
Snipe-IT before 8.1.18 allows unsafe deserialization.
< 8.1.18
Snipe-IT before 8.1.18 allows XSS.
< 8.1.0
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
all versions
An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious pay
all versions
Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing
< 7.0.10
Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. Thi
>= 4.6.17 and < 6.4.2
Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the gr
< 6.2.3
Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3.
< 6.2.2
Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2.
<= 6.0.14
Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/rese
< 6.0.14
Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.
< 6.0.10
Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.
< 6.0.11
Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.
< 6.0.10
Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.
all versions
An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attac
all versions
An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute ar
>= 3.0.0 and <= 5.3.7
In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in
< 5.4.4
Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.
< 5.4.3
Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The
< 5.4.3
Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerab
< 5.3.10
Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.
<= 5.3.10
Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.
< 5.3.11
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.
< 5.3.9
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.
< 5.3.9
Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.
< 5.3.8
Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.
< 5.3.7
snipe-it is vulnerable to Missing Authorization
< 5.3.6
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
< 5.3.5
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
<= 5.3.3
snipe-it is vulnerable to Improper Access Control
all versions
snipe-it is vulnerable to Server-Side Request Forgery (SSRF)
< 5.3.3
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
< 5.3.2
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
<= 5.3.1
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
<= 5.3.1
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
< 5.3.0
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
< 5.3.0
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
< 5.3.0
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
< 4.6.14
Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta values and the user's last name in the API.