Bounties
Partners
Community
Info
snipe / snipe-it
Project repository
A free open source IT asset/license management system
Submit a report
FIRST INTERACTION
WITHIN
1 DAY
REVIEW
WITHIN
5 DAYS
FIX
WITHIN
5 DAYS
CSRF in Send Reminder
Oct 11th 2023
hainguyen0207
•
Medium
Medium
•
CVE-2023-5511
CVE-2023-5511
Open Redirect Vulnerability
Oct 11th 2023
hainguyen0207
•
self closed
Stored Cross Site Scripting (XSS)
Oct 6th 2023
shahzaibak96
•
Medium
Medium
•
CVE-2023-5452
CVE-2023-5452
CSV Injection in CSV files generated by the backend
Sep 30th 2022
vautia
•
Low
Low
Reflected XSS on searchbar (on top)
Sep 12th 2022
mike993
•
not applicable
Stored Cross-Site Scripting (XSS)
Aug 29th 2022
vautia
•
Medium
Medium
•
CVE-2022-3035
CVE-2022-3035
Improper Authentication
Sep 16th 2022
vautia
•
Medium
Medium
•
CVE-2022-3173
CVE-2022-3173
Session Fixation
Aug 25th 2022
vautia
•
Medium
Medium
•
CVE-2022-2997
CVE-2022-2997
Username can be enumerated by password reset endpoint
Jun 22nd 2022
imlonghao
•
Low
Low
Able to create an user with a long password as well as long username
May 13th 2022
nithissh200
•
Low
Low
Session cookie is not invalidated on logout
May 1st 2022
nerrorsec
•
pending
Stored Cross Site Scripting vulnerability in the checked_out_to parameter
Apr 24th 2022
mylong
•
Critical
•
$55
Critical
•
$55
•
CVE-2022-1445
CVE-2022-1445
purchase_cost can be set negative
Apr 15th 2022
minhnb11
•
not applicable
Incorrect Privilege Assignment
Apr 28th 2022
minhnb11
•
not applicable
Bussiness Logic Error at checkout function
Apr 14th 2022
minhnb11
•
pending
Stored Cross Site Scripting vulnerability in Item name parameter
Apr 15th 2022
asura-n
•
Critical
•
$55
Critical
•
$55
•
CVE-2022-1380
CVE-2022-1380
Old sessions are not blocked by the login enable function.
Mar 29th 2022
lekhang123lc
•
High
•
$30
High
•
$30
•
CVE-2022-1155
CVE-2022-1155
Improper Access Control
Apr 28th 2022
shubh123-tri
•
Medium
•
$48.6
Medium
•
$48.6
•
CVE-2022-1511
CVE-2022-1511
Exposure of Sensitive Information to an Unauthorized Actor
Feb 11th 2022
thebinitghimire
•
Medium
Medium
•
CVE-2022-0569
CVE-2022-0569
Generation of Error Message Containing Sensitive Information
Feb 16th 2022
thebinitghimire
•
Medium
•
$3.4
Medium
•
$3.4
•
CVE-2022-0622
CVE-2022-0622
Improper Privilege Management
Feb 13th 2022
shubh123-tri
•
Medium
•
$55
Medium
•
$55
•
CVE-2022-0579
CVE-2022-0579
Incorrect Privilege Assignment
Feb 11th 2022
ranjit-git
•
Medium
•
$66
Medium
•
$66
Improper Privilege Management
Feb 14th 2022
ranjit-git
•
Medium
•
$77
Medium
•
$77
•
CVE-2022-0611
CVE-2022-0611
Improper Access Control
Jan 13th 2022
kstarkloff
•
Medium
•
$33.4
Medium
•
$33.4
•
CVE-2022-0178
CVE-2022-0178
Improper Access Control
Jan 11th 2022
haxatron
•
Medium
•
$105
Medium
•
$105
•
CVE-2022-0179
CVE-2022-0179
Cross-Site Request Forgery (CSRF)
Dec 17th 2021
haxatron
•
Medium
•
$48.6
Medium
•
$48.6
•
CVE-2021-4130
CVE-2021-4130
Cross-site Scripting (XSS) - Stored
Dec 13th 2021
laladee
•
Medium
Medium
•
CVE-2021-4108
CVE-2021-4108
Improper Access Control
Dec 9th 2021
haxatron
•
Medium
•
$95
Medium
•
$95
•
CVE-2021-4089
CVE-2021-4089
Server-Side Request Forgery (SSRF)
Dec 6th 2021
haxatron
•
Low
•
$106.4
Low
•
$106.4
•
CVE-2021-4075
CVE-2021-4075
Cross-site Scripting (XSS) - Stored
Nov 25th 2021
asura-n
•
Medium
Medium
•
CVE-2021-4018
CVE-2021-4018
Cross-site Scripting (XSS) - Stored
Nov 16th 2021
khanhchauminh
•
High
•
$40
High
•
$40
•
CVE-2021-3961
CVE-2021-3961
Cross-Site Request Forgery (CSRF)
Nov 8th 2021
hdvinnie
•
Medium
•
$39
Medium
•
$39
Cross-site Scripting (XSS) - Generic
Nov 9th 2021
haxatron
•
Low
•
$47.5
Low
•
$47.5
•
CVE-2021-3938
CVE-2021-3938
Cross-Site Request Forgery (CSRF)
Nov 5th 2021
haxatron
•
Medium
•
$123.5
Medium
•
$123.5
•
CVE-2021-3931
CVE-2021-3931
Cross-site Scripting (XSS) - Stored
Oct 15th 2021
noobpk
•
Medium
Medium
•
CVE-2021-3879
CVE-2021-3879
Insufficient Granularity of Access Control
Oct 8th 2021
takester
•
Medium
•
$40
Medium
•
$40
Cross-site Scripting (XSS) - Generic
Oct 6th 2021
noobpk
•
Medium
•
$10
Medium
•
$10
•
CVE-2021-3863
CVE-2021-3863
Cross-Site Request Forgery (CSRF)
Oct 5th 2021
am0o0
•
Medium
•
$120
Medium
•
$120
•
CVE-2021-3858
CVE-2021-3858
The UI Performs the Wrong Action
Oct 4th 2021
asura-n
•
Medium
•
$80
Medium
•
$80
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0