Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Snipeitapp

First CVE: Mar 27, 2019Active for: 7 yearsTotal CVEs: 71
37.2
VTI Score
Medium

Snipe-IT is an open-source asset-management platform deployed across IT organizations for inventory tracking and lifecycle management, presenting a focused but strategically important attack surface in many enterprise environments. The recurring vulnerability pattern centers on web-application security issues, particularly cross-site scripting, missing or improper authorization controls, and cross-site request forgery, which are characteristic of web-facing inventory and administrative interfaces. These weakness classes directly threaten the integrity of asset data and the privileges of administrative users who interact with the system. Defenders should treat Snipe-IT deployments as requiring routine security patching, particularly where the application is accessible to multiple users or exposed to untrusted networks; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
71
Total CVEs
More Total CVEs than 99% of tracked vendors
10.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Snipeitapp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 27, 2019
7 years ago
Most Recent CVE
Jul 10, 2026
15 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (71 CVEs).

71 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-55466HIGH
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and UploadedFilesController ser
Jul 10, 20268.737NONO
CVE-2026-37709CRITICAL
Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the
May 7, 20269.837NONO
CVE-2026-55516HIGH
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} checks access to the current maintenance record and asset but
Jul 10, 20267.736NONO
CVE-2026-54329HIGH
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass a
Jul 10, 20267.735NONO
CVE-2026-44832HIGH
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PA
May 26, 20268.835NONO
CVE-2026-55460HIGH
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.delete can directly POST to /use
Jul 10, 20267.133NONO
CVE-2026-55843MEDIUM
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and
Jul 10, 20266.532NONO
CVE-2025-63601CRITICAL
Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and
Nov 5, 20259.932NONO
CVE-2026-55452HIGH
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes th
Jul 10, 20267.331NONO
CVE-2026-55474MEDIUM
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path wi
Jul 10, 20266.531NONO
View all 71 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products71 CVEs
66%
30%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.4%)
Network70 (98.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low70 (98.6%)
High1 (1.4%)
Unknown0 (0.0%)
User Interaction
None36 (50.7%)
Unknown0 (0.0%)
Required35 (49.3%)
Privileges Required
Low47 (66.2%)
High9 (12.7%)
None15 (21.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (71 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Snipeitapp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Snipeitapp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Snipeitapp's Products

View all 6 CNAs →

Top CWEs