Snipe It

Vendor:

First CVE: Mar 27, 2019 · Active for 7 years

71
Total CVEs
More Total CVEs than 98% of tracked products
10.1
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Snipe It over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 27, 2019
7 years ago
Most Recent CVE
Jul 10, 2026
14 days ago

CVE Severity & Scoring

Snipe It71 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local1 (1.4%)
Network70 (98.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low70 (98.6%)
High1 (1.4%)
Unknown0 (0.0%)
User Interaction
None36 (50.7%)
Unknown0 (0.0%)
Required35 (49.3%)
Privileges Required
Low47 (66.2%)
High9 (12.7%)
None15 (21.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (71 CVEs).

71 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and UploadedFilesController ser
Jul 10, 20268.737NONO
Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the
May 7, 20269.837NONO
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} checks access to the current maintenance record and asset but
Jul 10, 20267.736NONO
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass a
Jul 10, 20267.735NONO
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PA
May 26, 20268.835NONO
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.delete can directly POST to /use
Jul 10, 20267.133NONO
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and
Jul 10, 20266.532NONO
Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and
Nov 5, 20259.932NONO
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes th
Jul 10, 20267.331NONO
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path wi
Jul 10, 20266.531NONO

Exploit Exposure

Signals from CVEs in this product scope (71 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.4% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (71 CVEs).

Media Mentions

Signals from CVEs in this product scope (71 CVEs).

Top CNAs Publishing CVEs For Snipe It

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.4.016.50.3%00
8.3.416.10.2%00
7.0.1328.30.4%00
6.0.224.80.9%00
6.0.015.31.0%00
5.3.1017.41.0%00
3.0.018.81.3%00