Known vulnerabilities in snipe-it - page 4

Vendor: snipe
Software: snipe-it
Software CPE: cpe:2.3:a:snipe:snipe-it:*:*:*:*:*:*:*:*
Total vulnerabilities: 112
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting snipe-it snipe-it is affected by 112 known vulnerabilities: 2 high, 25 medium, 84 low Critical High Medium Low

Vulnerabilities (112)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU142575 - Authorization Bypass Through User-Controlled Key
CWE-639 Medium
No
No
8.6.2 14.08.2026 SB20260814123
#VU142574 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-55481
CWE-79 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142573 - Improper Neutralization of Formula Elements in a CSV File
CVE-2026-55452
CWE-1236 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142572 - Improper Access Control
CVE-2026-55515
CWE-284 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142571 - Missing Authorization
CVE-2026-55516
CWE-862 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142570 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-61807
CWE-79 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142569 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2026-55461
CWE-601 Medium
No
No
8.6.2 14.08.2026 SB20260814123
#VU142568 - Improper Authorization
CVE-2026-55460
CWE-285 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142566 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-55464
CWE-79 Low
No
No
8.6.2 14.08.2026 SB20260814123
#VU142562 - Relative Path Traversal
CVE-2026-55474
CWE-23 Low
No
No
8.6.0 14.08.2026 SB2026060947
#VU142557 - Improper Privilege Management
CVE-2026-55843
CWE-269 Low
No
No
8.6.0 14.08.2026 SB2026060947
#VU134513 - Improper Access Control
CVE-2026-55542
CWE-284 Low
No
No
8.6.0 15.06.2026 SB2026060947
#VU134511 - Authorization Bypass Through User-Controlled Key
CVE-2026-55482
CWE-639 Low
No
No
8.5.0 15.06.2026 SB2026060948
#VU134510 - Improper Access Control
CVE-2026-55483
CWE-284 Medium
No
No
8.5.0 15.06.2026 SB2026060948
#VU134016 - Improper Access Control
CVE-2026-50550
CWE-284 Low
No
No
8.5.0 09.06.2026 SB2026060948
#VU134015 - Improper Restriction of Excessive Authentication Attempts
CVE-2026-49870
CWE-307 Low
No
No
8.6.0 09.06.2026 SB2026060947
#VU134014 - Improper Access Control
CVE-2026-49976
CWE-284 Low
No
No
8.6.0 09.06.2026 SB2026060947
#VU134013 - Improper Access Control
CVE-2026-48492
CWE-284 Low
No
No
8.6.0 09.06.2026 SB2026060947
#VU134012 - Improper Access Control
CVE-2026-48493
CWE-284 Low
No
No
8.6.0 09.06.2026 SB2026060947
#VU134011 - Improper Access Control
CVE-2026-48507
CWE-284 Low
No
No
8.6.0 09.06.2026 SB2026060947


Showing elements 61 - 80 out of 112