Known vulnerabilities in snipe-it 6.0.0 - page 2

Vendor: snipe
Software: snipe-it
Version: 6.0.0
Software CPE: cpe:2.3:a:snipe:snipe-it:*:*:*:*:*:*:*:*
Total vulnerabilities: 45
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting snipe-it version 6.0.0 snipe-it 6.0.0 is affected by 45 vulnerabilities: 2 high, 8 medium, 35 low Critical High Medium Low

Vulnerabilities (45)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU142562 - Relative Path Traversal
CVE-2026-55474
CWE-23 Low
No
No
8.6.0 14.08.2026 SB2026060947
#VU142557 - Improper Privilege Management
CVE-2026-55843
CWE-269 Low
No
No
8.6.0 14.08.2026 SB2026060947
#VU134513 - Improper Access Control
CVE-2026-55542
CWE-284 Low
No
No
8.6.0 15.06.2026 SB2026060947
#VU134512 - Improper Authorization
CWE-285 Low
No
No
8.4.1 15.06.2026 SB2026051174
#VU134511 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
8.5.0 15.06.2026 SB2026060948
#VU134510 - Improper Access Control
CWE-284 Medium
No
No
8.5.0 15.06.2026 SB2026060948
#VU134016 - Improper Access Control
CVE-2026-50550
CWE-284 Low
No
No
8.5.0 09.06.2026 SB2026060948
#VU134015 - Improper Restriction of Excessive Authentication Attempts
CVE-2026-49870
CWE-307 Low
No
No
8.6.0 09.06.2026 SB2026060947
#VU134014 - Improper Access Control
CVE-2026-49976
CWE-284 Low
No
No
8.6.0 09.06.2026 SB2026060947
#VU134013 - Improper Access Control
CVE-2026-48492
CWE-284 Low
No
No
8.6.0 09.06.2026 SB2026060947
#VU134012 - Improper Access Control
CVE-2026-48493
CWE-284 Low
No
No
8.6.0 09.06.2026 SB2026060947
#VU134011 - Improper Access Control
CVE-2026-48507
CWE-284 Low
No
No
8.6.0 09.06.2026 SB2026060947
#VU130988 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-44831
CWE-79 Low
No
No
8.4.1 11.05.2026 SB2026051174
#VU130987 - Improper Access Control
CVE-2026-44832
CWE-284 Medium
No
No
8.4.1 11.05.2026 SB2026051174
#VU130986 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2026-44833
CWE-601 Low
No
No
8.4.1 11.05.2026 SB2026051174
#VU130985 - Improper Access Control
CVE-2026-37709
CWE-284 Low
No
No
8.4.1 11.05.2026 SB2026051174
#VU87176 - Improper Control of Generation of Code ('Code Injection')
CVE-2024-25117
CWE-94 High
No
No
6.3.2 07.03.2024 SB2024030706
SB2024030707
SB2024071178
#VU85898 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-51651
CWE-22 Low
No
No
6.3.0 30.01.2024 SB2024013024
SB2024013025
#VU85894 - Uncontrolled Recursion
CVE-2023-50262
CWE-674 Medium
No
No
6.3.0 30.01.2024 SB2024013023
SB2024013025
#VU85893 - Uncontrolled Recursion
CVE-2023-50251
CWE-674 Medium
No
No
6.3.0 30.01.2024 SB2024013022
SB2024013025
SB2024071178


Showing elements 21 - 40 out of 45