snipe/snipe-it Security Advisories for v8.6.0 (4)
-
[MEDIUM] Snipe-IT: Stored DOM XSS via table selected-count IDs
PKSA-9ywr-ywdr-gcrt CVE-2026-61807 GHSA-c8qc-wf67-342w
Affected version: <8.6.2
Reported by:
GitHub -
[MEDIUM] Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET
PKSA-2v9y-4jt3-bxpm CVE-2026-55703 GHSA-r9r3-g9fp-3q4q
Affected version: <8.6.3
Reported by:
GitHub -
[HIGH] Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover
PKSA-9n96-zyz7-nxh9 CVE-2026-55694 GHSA-3hgv-jr5j-cg9x
Affected version: <8.6.3
Reported by:
GitHub -
[HIGH] Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection
PKSA-2tsw-c1yg-xhyc CVE-2026-54329 GHSA-pwpj-p52h-q484
Affected version: <=8.6.1
Reported by:
GitHub