Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

snipe-it — Vulnerabilities & Security Advisories 31

All 31 CVE vulnerabilities found in snipe-it, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for Snipe-IT, an open-source asset management system, categorized under various weakness types including common weakness enumerations and specific application flaws. The collection encompasses a broad spectrum of security issues ranging from cross-site scripting and SQL injection to privilege escalation and remote code execution vectors. These records cover significant vulnerability disclosures reported between 2016 and 2023, reflecting the evolution of the software’s security landscape over several major release cycles. By centralizing this data, the page serves as a comprehensive reference for security professionals, developers, and system administrators who need to assess the risk profile associated with this specific asset management tool. Users can utilize this resource to track vendor advisories and monitor the historical progression of security fixes implemented by the Snipe-IT team. It also allows for a deeper understanding of prevalent weakness classes within the application, helping teams identify patterns in how attackers have exploited the software in the past. Furthermore, the aggregation enables stakeholders to look up the product’s vulnerability history in a single location, facilitating faster risk assessments during deployment, auditing, or incident response scenarios. This structured overview aids in prioritizing remediation efforts and ensuring that systems running Snipe-IT are protected against the most critical and widely exploited flaws identified in the community and by security researchers.

Vendor: snipe

CVE IDTitleCVSSSeverityPublished
CVE-2026-55481 Snipe-IT: CSS Injection via `header_color` Setting CWE-79--2026-07-10
CVE-2026-55475 Snipe-IT: Import created_by can be overwritten CWE-863 5.7 Medium2026-07-10
CVE-2026-55469 Snipe-IT: Path traversal vulnerability via CSV import `image` field CWE-22 6.5 Medium2026-07-10
CVE-2026-55461 Snipe-IT: Open Redirect After User Edit CWE-601 6.1 Medium2026-07-10
CVE-2026-55479 Snipe-IT: Incorrect permission for legacy license checkin API CWE-863--2026-07-10
CVE-2026-55452 Snipe-IT: CSV formula injection in Activity Report export CWE-1236--2026-07-10
CVE-2026-55466 Snipe-IT: Stored XSS via inline-served attachment CWE-79--2026-07-10
CVE-2026-55515 Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint CWE-639 5.0 Medium2026-07-10
CVE-2026-55462 Snipe-IT: Authorization bypass on print inventory page CWE-863 4.3 Medium2026-07-10
CVE-2026-55464 Snipe-IT: Stored XSS via Markdown custom field CWE-79--2026-07-10
CVE-2026-55460 Snipe-IT: Authorization bypass on bulk editing users CWE-863 7.1 High2026-07-10
CVE-2026-55472 Snipe-IT: API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation CWE-863 4.3 Medium2026-07-10
CVE-2026-55476 Snipe-IT: Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter CWE-862--2026-07-10
CVE-2026-55478 Snipe-IT: Missing object-level authorization in Kits API CWE-639--2026-07-10
CVE-2026-55843 Snipe-IT: Improper Privilege Management CWE-269--2026-07-10
CVE-2026-55516 Snipe-IT: Cross-company asset maintenance re-parenting via API update CWE-639 7.7 High2026-07-10
CVE-2026-55474 Snipe-IT: Directory traversal in displaySig CWE-23--2026-07-10
CVE-2026-54329 Snipe-IT: Cross-Tenant Accessory Injection in Snipe-IT API CWE-862 8.5 High2026-07-10
CVE-2026-48492 Snipe-IT's selectlist visibility is too permissive CWE-862--2026-07-08
CVE-2026-55542 Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL CWE-862--2026-07-08
CVE-2026-48493 Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment CWE-863 5.5 Medium2026-06-23
CVE-2026-48507 Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users CWE-863 7.1 High2026-06-08
CVE-2026-44833 Snipe-IT: Open redirect vulnerability CWE-601 5.9 Medium2026-05-26
CVE-2026-44832 Snipe-IT: Privilege Escalation via API Permissions Assignment CWE-281--2026-05-26
CVE-2026-44831 Snipe-IT: XSS vulnerability in component notes CWE-79 4.8 Medium2026-05-26
CVE-2025-15602 Snipe-IT < 8.3.7 Mass Assignment Vulnerability Leading to Privilege Escalation CWE-915 8.8 High2026-03-06
CVE-2025-59713 Snipe-IT 代码问题漏洞 CWE-502 6.8 Medium2025-09-19
CVE-2025-59712 Snipe-IT 跨站脚本漏洞 CWE-79 6.4 Medium2025-09-19
CVE-2025-47226 Snipe-IT 安全漏洞 CWE-425 5.0 Medium2025-05-02
CVE-2024-5685 Broken Function Level Authorization (BFLA) in snipe/snipe-it CWE-862 7.6 High2024-06-14

All 31 known CVE vulnerabilities affecting snipe-it with full Chinese analysis, references, and POCs where available.