CVE-2026-55464
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Mar
CVSS
5.4
Medium
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: Jul 10, 2026 · Last modified: Jul 13, 2026 · CWE-79
0.2%EPSS · 30 days0.3%
2026-08-102026-09-07
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea custom field that executes arbitrary JavaScript when another user opens the asset detail page and clicks the link. This issue is fixed in version 8.6.2.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-818244.7 MED—
———The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.2hCVE-2026-696904.6 MED—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.2hCVE-2026-696153.5 LOW—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.2hCVE-2026-694177.3 HIG—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.2hCVE-2026-694027.3 HIG—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.2hCVE-2026-693569.3 CRI—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.2h