Known vulnerabilities in snipe-it 6.0.0

Vendor: snipe
Software: snipe-it
Version: 6.0.0
Software CPE: cpe:2.3:a:snipe:snipe-it:*:*:*:*:*:*:*:*
Total vulnerabilities: 45
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting snipe-it version 6.0.0 snipe-it 6.0.0 is affected by 45 vulnerabilities: 2 high, 8 medium, 35 low Critical High Medium Low

Vulnerabilities (45)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU142578 - Improper Access Control
CWE-284 Low
No
No
8.6.3 14.08.2026 SB20260814125
#VU142577 - Authorization Bypass Through User-Controlled Key
CVE-2026-55694
CWE-639 Low
No
No
8.6.3 14.08.2026 SB20260814125
#VU142576 - Missing Authorization
CVE-2026-55703
CWE-862 Low
No
No
8.6.3 14.08.2026 SB20260814125
#VU142575 - Authorization Bypass Through User-Controlled Key
CWE-639 Medium
No
No
8.6.2 14.08.2026 SB20260814123
#VU142574 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-55481
CWE-79 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142573 - Improper Neutralization of Formula Elements in a CSV File
CVE-2026-55452
CWE-1236 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142572 - Improper Access Control
CVE-2026-55515
CWE-284 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142571 - Missing Authorization
CVE-2026-55516
CWE-862 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142570 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-61807
CWE-79 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142569 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2026-55461
CWE-601 Medium
No
No
8.6.2 14.08.2026 SB20260814123
#VU142568 - Improper Authorization
CVE-2026-55460
CWE-285 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142567 - Improper Access Control
CVE-2026-55462
CWE-284 Low
No
No
8.6.1 14.08.2026 SB20260814124
#VU142565 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-55466
CWE-79 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142564 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-55469
CWE-22 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142563 - Improper Access Control
CVE-2026-55472
CWE-284 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142561 - Improper Access Control
CVE-2026-55475
CWE-284 Low
No
No
8.6.1 14.08.2026 SB20260814124
#VU142560 - Improper Access Control
CVE-2026-55476
CWE-284 Low
No
No
8.6.1 14.08.2026 SB20260814124
#VU142559 - Authorization Bypass Through User-Controlled Key
CVE-2026-55478
CWE-639 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142558 - Improper Access Control
CVE-2026-55479
CWE-284 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142556 - Improper Access Control
CVE-2026-54329
CWE-284 Medium
No
No
8.6.2 14.08.2026 SB20260814123


Showing elements 1 - 20 out of 45