CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

snipeitapp

snipe-it

46 known vulnerabilities · sorted by CVSS score

CVE-2025-63601
CRITICAL9.9

Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and execute system commands.

snipeitapp / snipe-it
Network
Published Nov 5, 2025
Page 1 of 3
CVE-2021-3858
HIGH8.8

snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

snipeitapp / snipe-it
Network
Published Oct 19, 2021
CVE-2021-4130
HIGH8.8

snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

snipeitapp / snipe-it
Network
Published Dec 18, 2021
CVE-2026-44832
HIGH8.8

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1. The API controller only strips the superuser key from the permissions array, allowing admin and all other permission keys to be set by any user who can update users. This vulnerability is fixed in 8.4.1.

snipeitapp / snipe-it
Network
Published May 26, 2026
CVE-2022-23064
HIGH8.8

In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This leads to account take over.

snipeitapp / snipe-it+5
Network
Published May 2, 2022
CVE-2023-5511
HIGH8.8

Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3.

snipeitapp / snipe-it
Network
Published Oct 11, 2023
CVE-2024-51093
HIGH8.7

Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the Snipe-IT system.

snipeitapp / snipe-it
Network
Published Nov 12, 2024
CVE-2022-2997
HIGH8.0

Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.

snipeitapp / snipe-it
Network
Published Aug 25, 2022
CVE-2024-51094
HIGH8.0

An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. When an administrator later accesses the People Management page, exports the data as a CSV file, and opens it, the injected payload will be executed, allowing the attacker to exfiltrate internal system data from the CSV file to a remote server.

snipeitapp / snipe-it
Network
Published Nov 12, 2024
CVE-2024-5685
HIGH7.6

Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.

snipeitapp / snipe-it
Network
Published Jun 14, 2024
CVE-2022-1155
HIGH7.4

Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.

snipeitapp / snipe-it+1
Network
Published Mar 30, 2022
CVE-2021-4075
HIGH7.2

snipe-it is vulnerable to Server-Side Request Forgery (SSRF)

snipeitapp / snipe-it
Network
Published Dec 6, 2021
CVE-2025-59713
MEDIUM6.8

Snipe-IT before 8.1.18 allows unsafe deserialization.

snipeitapp / snipe-it
Network
Published Sep 19, 2025
CVE-2024-48987
MEDIUM6.6

Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.

snipeitapp / snipe-it
Network
Published Oct 11, 2024
CVE-2022-1511
MEDIUM6.5

Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.

snipeitapp / snipe-it
Network
Published Apr 28, 2022
CVE-2022-0579
MEDIUM6.5

Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.

snipeitapp / snipe-it
Network
Published Feb 14, 2022
CVE-2025-59712
MEDIUM6.4

Snipe-IT before 8.1.18 allows XSS.

snipeitapp / snipe-it
Network
Published Sep 19, 2025
CVE-2022-0611
MEDIUM6.3

Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.

snipeitapp / snipe-it
Network
Published Feb 16, 2022
CVE-2022-0178
MEDIUM6.3

Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.

snipeitapp / snipe-it
Network
Published Jan 13, 2022
CVE-2019-10118
MEDIUM6.1

Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta values and the user's last name in the API.

snipeitapp / snipe-it
Network
Published Mar 27, 2019