๐Ÿ” CVE Alert

CVE-2026-61807

UNKNOWN 0.0

Snipe-IT: Stored DOM XSS via table selected-count IDs

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-side code reads the browser-decoded countId, uses it as a selector, concatenates countId.substring(1) into an HTML string, and passes the string to jQuery .after(). A crafted name can therefore execute JavaScript when an authenticated user views the manufacturer detail page or supplier detail page, potentially exposing data or actions available to that session. This issue is fixed in version 8.6.2.

CWE CWE-79
Vendor grokability
Product snipe-it
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for grokability snipe-it

Be the first to know when new unknown vulnerabilities affecting grokability snipe-it are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

grokability / snipe-it
< 8.6.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/grokability/snipe-it/security/advisories/GHSA-c8qc-wf67-342w github.com: https://github.com/grokability/snipe-it/commit/d12ad3d53869443b96b663ba3ce2673ef343da71 github.com: https://github.com/grokability/snipe-it/releases/tag/v8.6.2