PT-2026-39299 · Grokability+2 · Snipe-It+1

Lorenzofradeani

·

Published

2026-05-08

·

Updated

2026-05-26

·

CVE-2026-44831

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Snipe-IT versions prior to 8.4.1
Description Users with component view access can be affected by cross-site scripting (XSS), a flaw where malicious scripts are injected into trusted websites, due to an unescaped notes column.
Recommendations Update to version 8.4.1 or greater.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44831
GHSA-R42M-953Q-6VJX

Affected Products

Snipe-It
Snipe/Snipe-It