InvenTree
Inventree · 16 CVEs
InvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (`row_data`/`data`) and column…
Sep 21, 2026
InvenTree: Plugin-settings GET endpoints are readable without authentication
Sep 21, 2026
InvenTree: Report/Label print endpoints ignore per-model permissions
Sep 21, 2026
InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data without enforcing the model's vi…
Sep 21, 2026
InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credential Disclosure
Sep 21, 2026
InvenTree: Missing authorization on machine restart endpoint allows any authenticated user to interrupt production equi…
Sep 21, 2026
InvenTree has SSRF via Remote Image Download — No IP/Hostname Validation on remote_image URLs
Apr 8, 2026
InvenTree Plugin Installation - Insufficient Permissions
Apr 8, 2026
InvenTree has Arbitrary API Token Creation
Apr 8, 2026
InvenTree has SSTI in PART_NAME_FORMAT bypasses CVE-2026-27629 fix via {% if part.pk %} sandbox escape
Apr 8, 2026
InvenTree Affected by Privilege Escalation via API
Apr 8, 2026
InvenTree has Path Traversal In Report Templates
Mar 26, 2026
InvenTree Vulnerable to ORM Filter Injection
Mar 26, 2026
InvenTree Vulnerable to Server Side Template Injection (SSTI)
Feb 25, 2026
InvenTree has uncontrolled memory allocation via built-in label-sheet plugin
Jun 3, 2025
Stored Cross-site Scripting Vulnerability in Markdown Editor
Oct 7, 2024
Cross-site Scripting (XSS) - Stored in inventree/inventree
Sep 29, 2022
Allocation of Resources Without Limits or Throttling in inventree/inventree
Jun 20, 2022
Cross-site Scripting (XSS) - Stored in inventree/inventree
Jun 17, 2022
Improper Neutralization of Formula Elements in a CSV File in inventree/inventree
Jun 17, 2022
Unrestricted Upload of File with Dangerous Type in inventree/inventree
Jun 17, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-61747 | InvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (`row_data`/`data`) and column mappings | MEDIUM | 0.34% | Sep 21, 2026 |
| CVE-2026-61746 | InvenTree: Plugin-settings GET endpoints are readable without authentication | MEDIUM | 0.40% | Sep 21, 2026 |
| CVE-2026-61748 | InvenTree: Report/Label print endpoints ignore per-model permissions | MEDIUM | 0.42% | Sep 21, 2026 |
| CVE-2026-61744 | InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data without enforcing the model's view role | MEDIUM | 0.51% | Sep 21, 2026 |
| CVE-2026-61749 | InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credential Disclosure | MEDIUM | 0.48% | Sep 21, 2026 |
| CVE-2026-61745 | InvenTree: Missing authorization on machine restart endpoint allows any authenticated user to interrupt production equipment | MEDIUM | 0.43% | Sep 21, 2026 |
| CVE-2026-39362 | InvenTree has SSRF via Remote Image Download — No IP/Hostname Validation on remote_image URLs | MEDIUM | 0.30% | Apr 8, 2026 |
| CVE-2026-35479 | InvenTree Plugin Installation - Insufficient Permissions | MEDIUM | 0.37% | Apr 8, 2026 |
| CVE-2026-35478 | InvenTree has Arbitrary API Token Creation | HIGH | 0.43% | Apr 8, 2026 |
| CVE-2026-35477 | InvenTree has SSTI in PART_NAME_FORMAT bypasses CVE-2026-27629 fix via {% if part.pk %} sandbox escape | CRITICAL | 0.36% | Apr 8, 2026 |
| CVE-2026-35476 | InvenTree Affected by Privilege Escalation via API | HIGH | 0.24% | Apr 8, 2026 |
| CVE-2026-33531 | InvenTree has Path Traversal In Report Templates | MEDIUM | 0.38% | Mar 26, 2026 |
| CVE-2026-33530 | InvenTree Vulnerable to ORM Filter Injection | HIGH | 0.34% | Mar 26, 2026 |
| CVE-2026-27629 | InvenTree Vulnerable to Server Side Template Injection (SSTI) | HIGH | 0.55% | Feb 25, 2026 |
| CVE-2025-49000 | InvenTree has uncontrolled memory allocation via built-in label-sheet plugin | MEDIUM | 0.33% | Jun 3, 2025 |
| CVE-2024-47610 | Stored Cross-site Scripting Vulnerability in Markdown Editor | HIGH | 0.32% | Oct 7, 2024 |
| CVE-2022-3355 | Cross-site Scripting (XSS) - Stored in inventree/inventree | MEDIUM | 0.85% | Sep 29, 2022 |
| CVE-2022-2134 | Allocation of Resources Without Limits or Throttling in inventree/inventree | MEDIUM | 0.86% | Jun 20, 2022 |
| CVE-2022-2113 | Cross-site Scripting (XSS) - Stored in inventree/inventree | MEDIUM | 0.79% | Jun 17, 2022 |
| CVE-2022-2112 | Improper Neutralization of Formula Elements in a CSV File in inventree/inventree | HIGH | 1.28% | Jun 17, 2022 |
| CVE-2022-2111 | Unrestricted Upload of File with Dangerous Type in inventree/inventree | HIGH | 1.24% | Jun 17, 2022 |
Showing 1 to 16 of 16 CVEs