snipe/snipe-it Security Advisories for v1.2.3 (37)
- 
                        [MEDIUM] Snipe-IT allows unsafe deserializationPKSA-xzw3-k89w-sm61 CVE-2025-59713 GHSA-phwj-fgch-xvrj Affected version: <8.1.18 Reported by: 
 GitHub
- 
                        [MEDIUM] Snipe-IT allows XSSPKSA-hsvj-t2cd-6x2t CVE-2025-59712 GHSA-c9wp-pr7f-hfqm Affected version: <8.1.18 Reported by: 
 GitHub
- 
                        [MEDIUM] Grokability Snipe-IT has incorrect authorization for accessing asset informationPKSA-vcwy-q31n-p6vy CVE-2025-47226 GHSA-h3vp-qwmx-5j25 Affected version: <8.1.0 Reported by: 
 GitHub
- 
                        [HIGH] Cross Site Scripting vulnerability in Snipe-ITPKSA-b5q2-426v-y91n CVE-2024-51093 GHSA-hw9x-8m75-4vjq Affected version: <=7.0.13 Reported by: 
 GitHub
- 
                        [HIGH] Snipe-IT remote code executionPKSA-xdch-tcv5-mhm5 CVE-2024-48987 GHSA-57qh-vmjr-5jxg Affected version: <7.0.10 Reported by: 
 GitHub
- 
                        [HIGH] Snipe-IT allows users to promote or demote themselves or other usersPKSA-z8qx-662q-rf8y CVE-2024-5685 GHSA-544r-fc65-v832 Affected version: <6.4.2 Reported by: 
 GitHub
- 
                        [HIGH] Cross-Site Request Forgery (CSRF) in snipe/snipe-itPKSA-vwgv-c27j-814j CVE-2023-5511 GHSA-33vj-r6p6-x4p8 Affected version: <=6.2.2 Reported by: 
 GitHub
- 
                        [MEDIUM] Cross-site Scripting in snipe/snipe-itPKSA-cht9-1vc6-6bmf CVE-2023-5452 GHSA-rr5c-69c9-gj9f Affected version: <=6.2.1 Reported by: 
 GitHub
- 
                        [MEDIUM] Snipe-IT vulnerable to Cross Site Scripting for View Assigned AssetsPKSA-44wz-9w6n-4dr3 CVE-2022-44380 GHSA-363q-j92x-7543 Affected version: <6.0.14 Reported by: 
 GitHub
- 
                        [MEDIUM] Snipe-IT allows attackers to check whether a user account existsPKSA-jrdw-kz9p-4bz7 CVE-2022-44381 GHSA-qqv9-gqh5-7h99 Affected version: <=6.0.14 Reported by: 
 GitHub
- 
                        [MEDIUM] Snipe-IT vulnerable to Improper AuthenticationPKSA-7r6m-2yf6-yhdg CVE-2022-3173 GHSA-fhvv-p968-6vvj Affected version: <6.0.10 Reported by: 
 GitHub
- 
                        [MEDIUM] snipe-it vulnerable to cross-site scripting (XSS)PKSA-w688-w6zs-zd4h CVE-2022-3035 GHSA-rff2-vqm3-jpv5 Affected version: <6.0.11 Reported by: 
 GitHub
- 
                        [MEDIUM] Insufficient Session Expiration in snipe/snipe-itPKSA-rfx5-qvwj-94st CVE-2022-2997 GHSA-cmxc-9ghj-jp87 Affected version: <6.0.10 Reported by: 
 GitHub
- 
                        [MEDIUM] Snipe-IT 6.0.2 vulnerable to Cross-site ScriptingPKSA-z58z-h4zh-1zhj CVE-2022-32061 GHSA-xwqx-x38c-cw95 Affected version: <=6.0.2 Reported by: 
 GitHub
- 
                        [MEDIUM] Snipe-IT 6.0.2 vulnerable to Cross-site Scripting via arbitrary file upload in Update Branding SettingsPKSA-8j5v-fmm7-wt5m CVE-2022-32060 GHSA-w82x-xjjr-cjr5 Affected version: <=6.0.2 Reported by: 
 GitHub
- 
                        [MEDIUM] Snipe-IT XSS VulnerabilityPKSA-14vj-xv1g-g219 CVE-2019-10118 GHSA-fx98-8w93-4mxr Affected version: <4.6.14 Reported by: 
 GitHub
- 
                        [MEDIUM] Improper Access Control in snipe/snipe-itPKSA-mx1p-71nz-7bbw CVE-2022-1511 GHSA-p2vw-f87c-q597 Affected version: <5.4.4 Reported by: 
 GitHub
- 
                        [MEDIUM] Stored cross-site scripting in Snipe-ITPKSA-cry2-5f97-1776 CVE-2022-1445 GHSA-hpx4-xjp7-m4vr Affected version: <5.4.3 Reported by: 
 GitHub
- 
                        [MEDIUM] Cross-site Scripting in snipe-itPKSA-tysm-wwww-bphm CVE-2022-1380 GHSA-p885-prv3-m4xv Affected version: <5.4.3 Reported by: 
 GitHub
- 
                        [HIGH] Old sessions not blocked by login enable function in Snipe-ITPKSA-111v-cp4h-45pv CVE-2022-1155 GHSA-636j-7x7r-gvw2 Affected version: <5.4.2|>=6.0.0-RC-1,<=6.0.0-RC-5 Reported by: 
 GitHub
- 
                        [MEDIUM] Generation of Error Message Containing Sensitive Information in Snipe-ITPKSA-6qhy-57tc-w8br CVE-2022-0622 GHSA-pwwm-pwx2-2hw7 Affected version: <5.3.11 Reported by: 
 GitHub
- 
                        [HIGH] Improper Privilege Management in Snipe-ITPKSA-tnk3-ggr7-23qc CVE-2022-0611 GHSA-j57w-3c39-gpp5 Affected version: <5.3.11 Reported by: 
 GitHub
- 
                        [MEDIUM] Exposure of Sensitive Information in snipe/snipe-itPKSA-b3pc-3vj4-js4s CVE-2022-0569 GHSA-qpv2-jxc7-3638 Affected version: <5.3.10 Reported by: 
 GitHub
- 
                        [MEDIUM] Improper Privilege Management in Snipe-ITPKSA-b466-9p4g-g85g CVE-2022-0579 GHSA-v6vg-pxvv-g5cq Affected version: <5.3.9 Reported by: 
 GitHub
- 
                        [MEDIUM] Improper Access Control in snipe-itPKSA-gzsd-9krn-qpvt CVE-2022-0178 GHSA-xc47-3rch-cv57 Affected version: <=5.3.7 Reported by: 
 GitHub
- 
                        [MEDIUM] Incorrect Default Permissions and Improper Access Control in snipe-itPKSA-ytnn-96r3-d3kb CVE-2022-0179 GHSA-w3v3-cxq5-9vr4 Affected version: <5.3.7 Reported by: 
 GitHub
- 
                        [HIGH] snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)PKSA-168d-vfgc-8zkn CVE-2021-4130 GHSA-4w23-c97g-fq5v Affected version: <5.3.6 Reported by: 
 GitHub
- 
                        [MEDIUM] snipe-it is vulnerable to Improper Access ControlPKSA-v6jc-z85y-2xb2 CVE-2021-4089 GHSA-9vwf-54m9-gc4f Affected version: <5.3.4 Reported by: 
 GitHub
- 
                        [MEDIUM] snipe-it is vulnerable to Cross-site ScriptingPKSA-xn61-mcnh-2z6t CVE-2021-4108 GHSA-rxch-gp62-574w Affected version: <5.3.5 Reported by: 
 GitHub
- 
                        [HIGH] Server-Side Request Forgery in snipe/snipe-itPKSA-mycg-3z9s-m171 CVE-2021-4075 GHSA-553q-hpvp-q8pc Affected version: <=5.3.3 Reported by: 
 GitHub
- 
                        [MEDIUM] snipe-it is vulnerable to Cross-site ScriptingPKSA-j39k-svpb-czn5 CVE-2021-4018 GHSA-5fh3-25xr-g85h Affected version: <5.3.3 Reported by: 
 GitHub
- 
                        [HIGH] Cross-site Scripting in snipe/snipe-itPKSA-v67w-nqct-qm6c CVE-2021-3961 GHSA-c65v-p733-9796 Affected version: <5.3.2 Reported by: 
 GitHub
- 
                        [LOW] snipe-it is vulnerable to Cross-site ScriptingPKSA-f953-tv8q-pmys CVE-2021-3938 GHSA-2cqg-q7jm-j35c Affected version: <=5.3.1 Reported by: 
 GitHub
- 
                        [MEDIUM] snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)PKSA-xvn7-8ccy-j2pj CVE-2021-3931 GHSA-533p-cp2g-99wp Affected version: <=5.3.1 Reported by: 
 GitHub
- 
                        [MEDIUM] Cross-site Scripting in snipe-itPKSA-k1nv-3hks-9dm6 CVE-2021-3863 GHSA-5rg2-6qr5-2xp8 Affected version: <5.3.0 Reported by: 
 GitHub
- 
                        [MEDIUM] Cross-Site Request Forgery in snipe-itPKSA-v52w-gy13-9kjc CVE-2021-3858 GHSA-g92x-8m54-p89v Affected version: <5.3.0 Reported by: 
 GitHub
- 
                        [MEDIUM] Cross-site Scripting in snipe-itPKSA-4ht1-zxj3-7f11 CVE-2021-3879 GHSA-9g3v-j3cr-6fc6 Affected version: <5.3.0 Reported by: 
 GitHub