Home/Product/inventree project inventree
Product

inventree project inventree

15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-39362
< 1.2.7
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is enabled (op
7.1HIGH
CVE-2026-35479
< 1.2.7
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permissions can
6.6MEDIUM
CVE-2026-35478
>= 0.16.0 and <= 1.2.6
InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create
8.3HIGH
CVE-2026-35477
>= 1.2.3 and <= 1.2.6
InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FO
5.5MEDIUM
CVE-2026-35476
<= 1.2.6
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate thei
7.2HIGH
CVE-2026-33531
< 1.2.6
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report temp
6.5MEDIUM
CVE-2026-33530
< 1.2.6
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with bulk data o
7.7HIGH
CVE-2026-27629
< 1.2.3
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be hijacked to
5.9MEDIUM
CVE-2025-49000
< 0.17.13
InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in label-sheet pl
3.5LOW
CVE-2024-47610
< 0.16.5
InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for a registered user to
7.3HIGH
CVE-2022-3355
< 0.8.3
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3.
5.4MEDIUM
CVE-2022-2134
< 0.8.0
Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.
6.5MEDIUM
CVE-2022-2113
< 0.7.2
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2.
5.4MEDIUM
CVE-2022-2112
< 0.7.2
Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.
8.8HIGH
CVE-2022-2111
< 0.7.2
Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.
8.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin