CVE-2019-25264
- EPSS 0.03%
- Veröffentlicht 03.02.2026 16:52:41
- Zuletzt bearbeitet 04.02.2026 16:34:21
Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the acces...
CVE-2025-65622
- EPSS 0.04%
- Veröffentlicht 01.12.2025 00:00:00
- Zuletzt bearbeitet 03.12.2025 18:58:47
Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.
CVE-2025-65621
- EPSS 0.04%
- Veröffentlicht 01.12.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 18:58:57
Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.
CVE-2025-64027
- EPSS 0.02%
- Veröffentlicht 20.11.2025 00:00:00
- Zuletzt bearbeitet 26.11.2025 16:15:50
Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an invalid CSV file is uploaded, the application returns a progress_message value that is rendered as raw HTML in the admin i...
CVE-2025-63601
- EPSS 0.43%
- Veröffentlicht 05.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 16:15:56
Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and execute system commands.
CVE-2025-59713
- EPSS 0.02%
- Veröffentlicht 19.09.2025 00:00:00
- Zuletzt bearbeitet 23.09.2025 16:57:34
Snipe-IT before 8.1.18 allows unsafe deserialization.
CVE-2025-59712
- EPSS 0.01%
- Veröffentlicht 19.09.2025 00:00:00
- Zuletzt bearbeitet 23.09.2025 16:57:45
Snipe-IT before 8.1.18 allows XSS.
CVE-2025-47226
- EPSS 1.05%
- Veröffentlicht 02.05.2025 00:00:00
- Zuletzt bearbeitet 03.06.2025 14:44:17
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
- EPSS 0.37%
- Veröffentlicht 12.11.2024 21:15:14
- Zuletzt bearbeitet 22.05.2025 17:28:00
An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. When an administrator later accesses the People Management page, exports the data as a CSV f...
CVE-2024-51093
- EPSS 0.23%
- Veröffentlicht 12.11.2024 21:15:14
- Zuletzt bearbeitet 21.11.2024 18:15:11
Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin ...