CVE Tools

Snipe-it

131 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Snipe-it, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Snipe-it CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Snipe-it CVEs per month
MonthCVEs
2024-101
2024-112
2024-120
2025-010
2025-020
2025-030
2025-040
2025-051
2025-060
2025-070
2025-080
2025-092
2025-100
2025-112
2025-122
2026-010
2026-020
2026-031
2026-041
2026-054
2026-062
2026-0720
2026-0811
2026-0949

Severity

How the 131 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical22%
  • High3225%
  • Medium8870%
  • Low43%

Latest CVEs

The 15 most recently published vulnerabilities affecting Snipe-it.

  1. CVE-2026-62368Snipe-IT: Stored XSS via Custom Field name in asset-list column headers8.1
  2. CVE-2026-63493Snipe-IT: 2FA bypass via the API token flow—
  3. CVE-2026-63498Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API8.7
  4. CVE-2026-88894Snipe-IT before 8.7.2 Authorization Bypass via Predefined Kit Checkout5.4
  5. CVE-2026-86774Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy6.3
  6. CVE-2026-86773Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints5.4
  7. CVE-2026-86772Snipe-IT 8.6.3 Stored XSS via Department Names5.4
  8. CVE-2026-86771Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num7.6
  9. CVE-2026-86770Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation8.1
  10. CVE-2026-86769Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout4.3
  11. CVE-2026-86768Snipe-IT before 8.7.0 Improper Input Validation via API Checkout5.4
  12. CVE-2026-86767Snipe-IT before 8.7.0 Cross-Company Read via requested-assets5.0
  13. CVE-2026-86766Snipe-IT 8.6.3 Race Condition via Consumable Checkout6.5
  14. CVE-2026-86764Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components6.5
  15. CVE-2026-86765Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store