CVE WATCH / VULNERABILITY DETAIL

CVE-2026-62368

HIGHCVSS 8.1NVD feed

Published 24 September 2026 · tracked since 25 September 2026

Description

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-table header title. When another user opens an asset-list page as

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-62368 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-62368

HIGHCVSS 8.1NVD feed

Published 24 September 2026 · tracked since 25 September 2026

Description

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-table header title. When another user opens an asset-list page as

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]