Snipe-IT is an open-source asset-management platform deployed across IT organizations for inventory tracking and lifecycle management, presenting a focused but strategically important attack surface in many enterprise environments. The recurring vulnerability pattern centers on web-application security issues, particularly cross-site scripting, missing or improper authorization controls, and cross-site request forgery, which are characteristic of web-facing inventory and administrative interfaces. These weakness classes directly threaten the integrity of asset data and the privileges of administrative users who interact with the system. Defenders should treat Snipe-IT deployments as requiring routine security patching, particularly where the application is accessible to multiple users or exposed to untrusted networks; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Snipeitapp over time
Signals from CVEs in this vendor scope (71 CVEs).
71 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-55466HIGH Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and UploadedFilesController ser | Jul 10, 2026 | 8.7 | 37 | NO | NO |
CVE-2026-37709CRITICAL Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the | May 7, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-55516HIGH Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} checks access to the current maintenance record and asset but | Jul 10, 2026 | 7.7 | 36 | NO | NO |
CVE-2026-54329HIGH Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass a | Jul 10, 2026 | 7.7 | 35 | NO | NO |
CVE-2026-44832HIGH Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PA | May 26, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-55460HIGH Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.delete can directly POST to /use | Jul 10, 2026 | 7.1 | 33 | NO | NO |
CVE-2026-55843MEDIUM Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and | Jul 10, 2026 | 6.5 | 32 | NO | NO |
CVE-2025-63601CRITICAL Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and | Nov 5, 2025 | 9.9 | 32 | NO | NO |
CVE-2026-55452HIGH Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes th | Jul 10, 2026 | 7.3 | 31 | NO | NO |
CVE-2026-55474MEDIUM Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path wi | Jul 10, 2026 | 6.5 | 31 | NO | NO |
Signals from CVEs in this vendor scope (71 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Snipeitapp.
Media articles that mention a CVE ID that affects a product developed by Snipeitapp — matched by CVE ID, not by vendor name.