Components
Vulnerabilities
Pricing
MCP
API
Docs
Sign up
Login
snipe/snipe-it v8.3.3 | Vulnerabilities | Sonatype Guide
composer
snipe
snipe-it
v8.3.3
snipe-it v8.3.3
snipe
Published
Oct 6, 2025
•
Policy
compliance
composer Registry
Developer Trust Score
N/A
Recommended Version:
x.y.z
Latest version with 0 known vulnerabilities that meets your policy.
Compare Versions
Overview
Overview
Versions
275
Versions
275
Vulnerabilities
5
Vulnerabilities
5
Dependencies
0
Dependencies
0
Severity
Critical
(0)
High
(1)
Medium
(4)
Low
(0)
CVSS Score
0.0
10.0
EPSS Score
0.0
1.0
Malware
KEV Status
Published
Filter
Sort: Published (Newest first)
8.8
CVE-2025-15602
Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account, including the Super Admin account. By changing the email address of the Super Admin and triggering a password reset, an attacker can fully take over the Super Admin account, resulting in complete administrative control of the Snipe-IT instance.
affected
Severity
High
Published
Mar 10, 2026
5.4
CVE-2025-65622
Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.
affected
Severity
Medium
Published
Dec 4, 2025
5.4
CVE-2025-65621
Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.
affected
Severity
Medium
Published
Dec 3, 2025
4.8
CVE-2022-32060
An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
affected
Severity
Medium
Published
Jul 11, 2022
4.8
CVE-2022-32061
An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
affected
Severity
Medium
Published
Jul 11, 2022