Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-r42m-953q-6vjx | Snipe-IT has Stored XSS via Component Checkout Notes (v8.4.0) |
Wed, 27 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grokability
Grokability snipe-it Snipeitapp Snipeitapp snipe-it |
|
| CPEs | cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Grokability
Grokability snipe-it Snipeitapp Snipeitapp snipe-it |
Tue, 26 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1. | |
| Title | Snipe-IT: XSS vulnerability in component notes | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-27T16:08:45.980Z
Reserved: 2026-05-07T21:21:48.351Z
Link: CVE-2026-44831
Updated: 2026-05-27T16:08:41.002Z
Status : Analyzed
Published: 2026-05-26T20:16:20.027
Modified: 2026-06-17T10:51:24.310
Link: CVE-2026-44831
No data.
OpenCVE Enrichment
Updated: 2026-05-26T20:30:15Z
Github GHSA