Snipe-IT
Grokability · 84 CVEs
Snipe-IT: Stored XSS via Custom Field name in asset-list column headers
Sep 24, 2026
Snipe-IT: 2FA bypass via the API token flow
Sep 24, 2026
Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API
Sep 24, 2026
Snipe-IT before 8.7.2 Authorization Bypass via Predefined Kit Checkout
Sep 10, 2026
Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy
Sep 9, 2026
Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints
Sep 9, 2026
Snipe-IT 8.6.3 Stored XSS via Department Names
Sep 9, 2026
Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num
Sep 9, 2026
Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation
Sep 9, 2026
Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout
Sep 9, 2026
Snipe-IT before 8.7.0 Improper Input Validation via API Checkout
Sep 9, 2026
Snipe-IT before 8.7.0 Cross-Company Read via requested-assets
Sep 9, 2026
Snipe-IT 8.6.3 Race Condition via Consumable Checkout
Sep 9, 2026
Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint
Sep 9, 2026
Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components
Sep 9, 2026
snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer
Sep 9, 2026
Snipe-IT before 8.7.0 Authentication Bypass via API Middleware
Sep 9, 2026
snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints
Sep 9, 2026
snipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flag
Sep 9, 2026
Snipe-IT before 8.7.0 Missing Authorization via asset-history CSV importer
Sep 9, 2026
Snipe-IT before 8.7.0 License Key Exposure via CSV Export
Sep 9, 2026
Snipe-IT before 8.7.0 Information Disclosure via Custom Fields
Sep 9, 2026
Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState
Sep 9, 2026
Snipe-IT 4.2.0 through 8.6.3 Permission Bypass via OAuth
Sep 9, 2026
Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients
Sep 9, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-62368 | Snipe-IT: Stored XSS via Custom Field name in asset-list column headers | HIGH | 0.35% | Sep 24, 2026 |
| CVE-2026-63493 | Snipe-IT: 2FA bypass via the API token flow | HIGH | 0.27% | Sep 24, 2026 |
| CVE-2026-63498 | Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API | HIGH | 0.21% | Sep 24, 2026 |
| CVE-2026-88894 | Snipe-IT before 8.7.2 Authorization Bypass via Predefined Kit Checkout | MEDIUM | 0.26% | Sep 10, 2026 |
| CVE-2026-86774 | Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy | MEDIUM | 0.29% | Sep 9, 2026 |
| CVE-2026-86773 | Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints | MEDIUM | 0.25% | Sep 9, 2026 |
| CVE-2026-86772 | Snipe-IT 8.6.3 Stored XSS via Department Names | MEDIUM | 0.25% | Sep 9, 2026 |
| CVE-2026-86771 | Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num | HIGH | 0.32% | Sep 9, 2026 |
| CVE-2026-86770 | Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation | HIGH | 0.57% | Sep 9, 2026 |
| CVE-2026-86769 | Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout | MEDIUM | 0.28% | Sep 9, 2026 |
| CVE-2026-86768 | Snipe-IT before 8.7.0 Improper Input Validation via API Checkout | MEDIUM | 0.35% | Sep 9, 2026 |
| CVE-2026-86767 | Snipe-IT before 8.7.0 Cross-Company Read via requested-assets | MEDIUM | 0.33% | Sep 9, 2026 |
| CVE-2026-86766 | Snipe-IT 8.6.3 Race Condition via Consumable Checkout | HIGH | 0.35% | Sep 9, 2026 |
| CVE-2026-86765 | Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint | HIGH | 0.40% | Sep 9, 2026 |
| CVE-2026-86764 | Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components | HIGH | 0.37% | Sep 9, 2026 |
| CVE-2026-86763 | snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer | MEDIUM | 0.27% | Sep 9, 2026 |
| CVE-2026-86762 | Snipe-IT before 8.7.0 Authentication Bypass via API Middleware | HIGH | 0.47% | Sep 9, 2026 |
| CVE-2026-86761 | snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints | MEDIUM | 0.36% | Sep 9, 2026 |
| CVE-2026-86760 | snipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flag | MEDIUM | 0.38% | Sep 9, 2026 |
| CVE-2026-86759 | Snipe-IT before 8.7.0 Missing Authorization via asset-history CSV importer | HIGH | 0.37% | Sep 9, 2026 |
| CVE-2026-86758 | Snipe-IT before 8.7.0 License Key Exposure via CSV Export | HIGH | 0.41% | Sep 9, 2026 |
| CVE-2026-86757 | Snipe-IT before 8.7.0 Information Disclosure via Custom Fields | HIGH | 0.37% | Sep 9, 2026 |
| CVE-2026-86756 | Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState | MEDIUM | 0.33% | Sep 9, 2026 |
| CVE-2026-86755 | Snipe-IT 4.2.0 through 8.6.3 Permission Bypass via OAuth | MEDIUM | 0.27% | Sep 9, 2026 |
| CVE-2026-86754 | Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients | HIGH | 0.34% | Sep 9, 2026 |
Showing 1 to 25 of 84 CVEs