Cross-site scripting in snipe-it - CVE-2026-61807
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in the victim\'s browser.
The vulnerability exists due to cross-site scripting in the table component when rendering stored manufacturer or supplier names into selected-count identifiers. A remote user can inject a crafted manufacturer or supplier name to execute arbitrary JavaScript in the victim\'s browser.
User interaction is required to view an affected manufacturer or supplier detail page.