Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Inventree HIGH 7.1
CVE-2026-39362

InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is enabled (opt-in), authenticate…

Fix: 1.2.7+
Fix from $1,950 2026-04-08
Inventree CRITICAL 9.9
CVE-2026-35477

InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to u…

Fix: after 1.2.6
Fix from $2,300 2026-04-08
Inventree HIGH 8.1
CVE-2026-35478

InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token a…

Fix: after 1.2.6
Fix from $1,950 2026-04-08
Inventree MEDIUM 6.5
CVE-2026-33530

InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with bulk data operations can be hi…

Fix: 1.2.6+
Fix from $1,600 2026-03-26
Inventree MEDIUM 6.5
CVE-2026-33531

InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report template engine allows …

Fix: 1.2.6+
Fix from $1,600 2026-03-26
Inventree HIGH 8.8
CVE-2026-27629

InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be hijacked to expose secure info…

Fix: 1.2.3+
Fix from $1,950 2026-02-25
Inventree MEDIUM 5.7
CVE-2025-49000

InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper…

Fix: 0.17.13+
Fix from $1,600 2025-06-03
Inventree MEDIUM 5.4
CVE-2024-47610

InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for a registered user to store javascript i…

Fix: 0.16.5+
Fix from $1,600 2024-10-07
Inventree MEDIUM 5.4
CVE-2022-3355

Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3.

Fix: 0.8.3+
Fix from $1,600 2022-09-29
Inventree MEDIUM 6.5
CVE-2022-2134

Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.

Fix: 0.8.0+
Fix from $1,600 2022-06-20
Inventree HIGH 8.8
CVE-2022-2111

Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.

Fix: 0.7.2+
Fix from $1,950 2022-06-17
Inventree HIGH 8.8
CVE-2022-2112

Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.

Fix: 0.7.2+
Fix from $1,950 2022-06-17
Inventree MEDIUM 5.4
CVE-2022-2113

Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2.

Fix: 0.7.2+
Fix from $1,600 2022-06-17