InvenTree

Inventree · 16 CVEs

CVE-2026-61747
MEDIUM

InvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (`row_data`/`data`) and column…

Sep 21, 2026

CVE-2026-61746
MEDIUM

InvenTree: Plugin-settings GET endpoints are readable without authentication

Sep 21, 2026

CVE-2026-61748
MEDIUM

InvenTree: Report/Label print endpoints ignore per-model permissions

Sep 21, 2026

CVE-2026-61744
MEDIUM

InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data without enforcing the model's vi…

Sep 21, 2026

CVE-2026-61749
MEDIUM

InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credential Disclosure

Sep 21, 2026

CVE-2026-61745
MEDIUM

InvenTree: Missing authorization on machine restart endpoint allows any authenticated user to interrupt production equi…

Sep 21, 2026

CVE-2026-39362
MEDIUM

InvenTree has SSRF via Remote Image Download — No IP/Hostname Validation on remote_image URLs

Apr 8, 2026

CVE-2026-35479
MEDIUM

InvenTree Plugin Installation - Insufficient Permissions

Apr 8, 2026

CVE-2026-35478
HIGH

InvenTree has Arbitrary API Token Creation

Apr 8, 2026

CVE-2026-35477
CRITICAL

InvenTree has SSTI in PART_NAME_FORMAT bypasses CVE-2026-27629 fix via {% if part.pk %} sandbox escape

Apr 8, 2026

CVE-2026-35476
HIGH

InvenTree Affected by Privilege Escalation via API

Apr 8, 2026

CVE-2026-33531
MEDIUM

InvenTree has Path Traversal In Report Templates

Mar 26, 2026

CVE-2026-33530
HIGH

InvenTree Vulnerable to ORM Filter Injection

Mar 26, 2026

CVE-2026-27629
HIGH

InvenTree Vulnerable to Server Side Template Injection (SSTI)

Feb 25, 2026

CVE-2025-49000
MEDIUM

InvenTree has uncontrolled memory allocation via built-in label-sheet plugin

Jun 3, 2025

CVE-2024-47610
HIGH

Stored Cross-site Scripting Vulnerability in Markdown Editor

Oct 7, 2024

CVE-2022-3355
MEDIUM

Cross-site Scripting (XSS) - Stored in inventree/inventree

Sep 29, 2022

CVE-2022-2134
MEDIUM

Allocation of Resources Without Limits or Throttling in inventree/inventree

Jun 20, 2022

CVE-2022-2113
MEDIUM

Cross-site Scripting (XSS) - Stored in inventree/inventree

Jun 17, 2022

CVE-2022-2112
HIGH

Improper Neutralization of Formula Elements in a CSV File in inventree/inventree

Jun 17, 2022

CVE-2022-2111
HIGH

Unrestricted Upload of File with Dangerous Type in inventree/inventree

Jun 17, 2022

Showing 1 to 16 of 16 CVEs