Known vulnerabilities in snipe-it - page 3

Vendor: snipe
Software: snipe-it
Software CPE: cpe:2.3:a:snipe:snipe-it:*:*:*:*:*:*:*:*
Total vulnerabilities: 112
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting snipe-it snipe-it is affected by 112 known vulnerabilities: 2 high, 25 medium, 84 low Critical High Medium Low

Vulnerabilities (112)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU145118 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-62368
CWE-79 Low
No
No
8.7.0 25.08.2026 SB2026082531
#VU145117 - Improper Access Control
CVE-2026-63493
CWE-284 Medium
No
No
8.7.0 25.08.2026 SB2026082531
#VU145116 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-63498
CWE-79 Low
No
No
8.7.0 25.08.2026 SB2026082531
#VU145115 - Incorrect Authorization
CWE-863 Medium
No
No
8.7.0 25.08.2026 SB2026082531
#VU145114 - Incorrect Authorization
CWE-863 Low
No
No
8.7.0 25.08.2026 SB2026082531
#VU145113 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
8.7.0 25.08.2026 SB2026082531
#VU145112 - Server-Side Request Forgery (SSRF)
CWE-918 Low
No
No
8.7.0 25.08.2026 SB2026082531
#VU142579 - Improper Access Control
CVE-2026-55643
CWE-284 Medium
No
No
8.6.3 14.08.2026 SB20260814125
#VU142578 - Improper Access Control
CWE-284 Low
No
No
8.6.3 14.08.2026 SB20260814125
#VU142577 - Authorization Bypass Through User-Controlled Key
CVE-2026-55694
CWE-639 Low
No
No
8.6.3 14.08.2026 SB20260814125
#VU142576 - Missing Authorization
CVE-2026-55703
CWE-862 Low
No
No
8.6.3 14.08.2026 SB20260814125
#VU142567 - Improper Access Control
CVE-2026-55462
CWE-284 Low
No
No
8.6.1 14.08.2026 SB20260814124
#VU142565 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-55466
CWE-79 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142564 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-55469
CWE-22 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142563 - Improper Access Control
CVE-2026-55472
CWE-284 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142561 - Improper Access Control
CVE-2026-55475
CWE-284 Low
No
No
8.6.1 14.08.2026 SB20260814124
#VU142560 - Improper Access Control
CVE-2026-55476
CWE-284 Low
No
No
8.6.1 14.08.2026 SB20260814124
#VU142559 - Authorization Bypass Through User-Controlled Key
CVE-2026-55478
CWE-639 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142558 - Improper Access Control
CVE-2026-55479
CWE-284 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142556 - Improper Access Control
CVE-2026-54329
CWE-284 Medium
No
No
8.6.2 14.08.2026 SB20260814123


Showing elements 41 - 60 out of 112