Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-39362 InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is enabled (opt-in), authenticate… Inventree 1.2.7+ Fix from $1,9502026-04-08 CRITICAL 9.9 CVE-2026-35477 InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to u… Inventree after 1.2.6 Fix from $2,3002026-04-08 HIGH 8.1 CVE-2026-35478 InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token a… Inventree after 1.2.6 Fix from $1,9502026-04-08 MEDIUM 6.5 CVE-2026-33530 InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with bulk data operations can be hi… Inventree 1.2.6+ Fix from $1,6002026-03-26 MEDIUM 6.5 CVE-2026-33531 InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report template engine allows … Inventree 1.2.6+ Fix from $1,6002026-03-26 HIGH 8.8 CVE-2026-27629 InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be hijacked to expose secure info… Inventree 1.2.3+ Fix from $1,9502026-02-25 MEDIUM 5.7 CVE-2025-49000 InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper… Inventree 0.17.13+ Fix from $1,6002025-06-03 MEDIUM 5.4 CVE-2024-47610 InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for a registered user to store javascript i… Inventree 0.16.5+ Fix from $1,6002024-10-07 MEDIUM 5.4 CVE-2022-3355 Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3. Inventree 0.8.3+ Fix from $1,6002022-09-29 MEDIUM 6.5 CVE-2022-2134 Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0. Inventree 0.8.0+ Fix from $1,6002022-06-20 HIGH 8.8 CVE-2022-2111 Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2. Inventree 0.7.2+ Fix from $1,9502022-06-17 HIGH 8.8 CVE-2022-2112 Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2. Inventree 0.7.2+ Fix from $1,9502022-06-17 MEDIUM 5.4 CVE-2022-2113 Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2. Inventree 0.7.2+ Fix from $1,6002022-06-17