Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ya3Raj

#20590of 56,330
13.7Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-89040
8.3
2026-09-09
Git · Snipe-It · CVE-2026-86771
Snipe-IT versions before 8.7.0 fail to HTML-escape the employee num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function. Attackers can craft a malicious employee num value containing an img tag with an arbitrary HTTP(S) URL to trigger server-side requests to internal services, cloud metadata endpoints, or external targets when a victim signs an asset acceptance.
PT-2026-89041
5.4
2026-09-09
Git · Snipe-It · CVE-2026-86772
Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without departments.view permission. Users with departments.edit permission can inject malicious scripts into department names that execute in the browsers of all department members when they load their My Assets page.