📦 Snipe It

by Snipeitapp

🔍 What is Snipe It?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-63601

CRITICAL CVSS 9.9 Nov 5, 2025

CVE-2025-63601 is a critical remote code execution vulnerability in Snipe-IT asset management software. Authenticated attackers can upload malicious backup files containing arbitrary files and execute...

CVE-2024-51093

HIGH CVSS 8.7 Nov 12, 2024

A stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT v7.0.13 allows attackers to upload malicious XML files containing JavaScript. When executed, this can escalate privileges to super admin, ...

CVE-2023-5511

HIGH CVSS 8.8 Oct 11, 2023

This CSRF vulnerability in Snipe-IT allows attackers to trick authenticated users into performing unintended actions without their consent. It affects all users of Snipe-IT prior to version 6.2.3 who ...

CVE-2022-23064

HIGH CVSS 8.8 May 2, 2022

CVE-2022-23064 is a host header injection vulnerability in Snipe-IT that allows attackers to send password reset links pointing to attacker-controlled servers. When users click these links, their pass...

CVE-2022-1155

HIGH CVSS 7.4 Mar 30, 2022

This vulnerability in Snipe-IT allows attackers to bypass authentication by reusing old sessions even after the login enable function is activated. It affects all Snipe-IT instances prior to version 5...

CVE-2021-4075

HIGH CVSS 7.2 Dec 6, 2021

CVE-2021-4075 is a Server-Side Request Forgery (SSRF) vulnerability in Snipe-IT that allows attackers to make the application send unauthorized requests to internal systems. This could lead to informa...

CVE-2021-3858

HIGH CVSS 8.8 Oct 19, 2021

CVE-2021-3858 is a Cross-Site Request Forgery (CSRF) vulnerability in Snipe-IT that allows attackers to trick authenticated users into performing unintended actions. This affects all Snipe-IT users wi...

CVE-2025-65622

MEDIUM CVSS 5.4 Dec 1, 2025

This stored cross-site scripting (XSS) vulnerability in Snipe-IT allows authenticated users with low privileges to inject malicious JavaScript into the Locations 'Country' field. When other users view...

CVE-2025-65621

MEDIUM CVSS 5.4 Dec 1, 2025

This stored cross-site scripting (XSS) vulnerability in Snipe-IT allows authenticated users with low privileges to inject malicious JavaScript that executes in administrator sessions. This enables pri...

CVE-2025-64027

MEDIUM CVSS 6.1 Nov 20, 2025

Snipe-IT v8.3.4 contains a reflected XSS vulnerability in the CSV import workflow where invalid file uploads return unsanitized HTML in progress messages. An authenticated attacker can inject maliciou...

CVE-2025-59713

MEDIUM CVSS 6.8 Sep 19, 2025

CVE-2025-59713 is an unsafe deserialization vulnerability in Snipe-IT versions before 8.1.18 that could allow remote code execution. This affects all organizations using vulnerable Snipe-IT instances ...

CVE-2025-59712

MEDIUM CVSS 6.4 Sep 19, 2025

CVE-2025-59712 is a cross-site scripting (XSS) vulnerability in Snipe-IT asset management software. It allows attackers to inject malicious scripts into web pages viewed by other users. Organizations ...

CVE-2025-47226

MEDIUM CVSS 5.0 May 2, 2025

CVE-2025-47226 is an authorization bypass vulnerability in Snipe-IT that allows unauthorized access to asset information. Attackers can exploit incorrect authorization checks to view sensitive asset d...

CVE-2024-48987

MEDIUM CVSS 6.6 Oct 11, 2024

Snipe-IT versions before 7.0.10 contain a remote code execution vulnerability via cookie serialization when an attacker obtains the APP_KEY. This allows unauthenticated attackers to execute arbitrary ...

CVE-2022-0611

MEDIUM CVSS 6.3 Feb 16, 2022

CVE-2022-0611 is a missing authorization vulnerability in Snipe-IT asset management software that allows authenticated users to access unauthorized functionality. This affects all Snipe-IT installatio...

CVE-2022-0579

MEDIUM CVSS 6.5 Feb 14, 2022

CVE-2022-0579 is a missing authorization vulnerability in Snipe-IT asset management software that allows authenticated users to access unauthorized functionality. This affects all Snipe-IT installatio...