Open source asset management system built on Laravel.
snipe/[email protected] has vulnerabilities — update to latest
Update to >= 6.0.0-GM to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| medium | CVE-2021-3931 | snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) | — |
| high | CVE-2021-4075 | Server-Side Request Forgery in snipe/snipe-it | 6.0.0-GM |
| medium | CVE-2025-64027 | Snipe-IT has Cross-site Scripting vulnerability in CSV import workflow | — |
| high | CVE-2024-51093 | Cross Site Scripting vulnerability in Snipe-IT | — |
| medium | CVE-2022-44381 | Snipe-IT allows attackers to check whether a user account exists | — |
| medium | CVE-2022-32060 | Snipe-IT 6.0.2 vulnerable to Cross-site Scripting via arbitrary file upload in Update Branding Settings | — |
| medium | CVE-2022-32061 | Snipe-IT 6.0.2 vulnerable to Cross-site Scripting | — |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/composer/snipe/snipe-itLast updated · 2026-04-07T18:14:08+00:00