Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

InvenTree — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in InvenTree, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations related to the InvenTree open-source inventory management system. It compiles security advisories and vulnerability reports published by the vendor and community, focusing on weaknesses affecting the application’s core functionality, API interfaces, and deployment configurations. The collection covers known issues identified from the system’s initial release through the present day, ensuring a comprehensive historical record of security incidents. Visitors can track the vendor’s advisory history to understand how response times and remediation efforts have evolved over time. Users can also analyze specific weakness classes, such as SQL injection or cross-site scripting, to see their prevalence and impact within the InvenTree ecosystem. Additionally, the page allows for a detailed lookup of the product’s vulnerability history, providing context on severity levels, fixed versions, and affected components. This resource is designed for security researchers, system administrators, and developers who need to assess the risk profile of InvenTree deployments. By centralizing this information, the page facilitates better risk management and informed decision-making regarding upgrades and patching strategies. It serves as a neutral, factual reference point without editorial commentary or promotional content.

Vendor: inventree

CVE ID Title CVSS Severity Published
CVE-2026-61748 InvenTree: Report/Label print endpoints ignore per-model permissions CWE-639 4.3 Medium 2026-09-21
CVE-2026-61746 InvenTree: Plugin-settings GET endpoints are readable without authentication CWE-200 5.3 Medium 2026-09-21
CVE-2026-61744 InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data without enforcing the model's view role CWE-639 6.5 Medium 2026-09-21
CVE-2026-61747 InvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (`row_data`/`data`) and column mappings CWE-639 4.3 Medium 2026-09-21
CVE-2026-61749 InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credential Disclosure CWE-200 6.5 Medium 2026-09-21
CVE-2026-61745 InvenTree: Missing authorization on machine restart endpoint allows any authenticated user to interrupt production equipment CWE-862 4.3 Medium 2026-09-21
CVE-2026-39362 InvenTree has SSRF via Remote Image Download — No IP/Hostname Validation on remote_image URLs CWE-918 7.1AI High AI 2026-04-08
CVE-2026-35479 InvenTree Plugin Installation - Insufficient Permissions CWE-285 6.6 Medium 2026-04-08
CVE-2026-35476 InvenTree Affected by Privilege Escalation via API CWE-285 7.2 High 2026-04-08
CVE-2026-35478 InvenTree has Arbitrary API Token Creation CWE-639 8.3 High 2026-04-08
CVE-2026-35477 InvenTree has SSTI in PART_NAME_FORMAT bypasses CVE-2026-27629 fix via {% if part.pk %} sandbox escape CWE-1336 5.5 Medium 2026-04-08
CVE-2026-33531 InvenTree has Path Traversal In Report Templates CWE-89 4.9 - 2026-03-26
CVE-2026-33530 InvenTree Vulnerable to ORM Filter Injection CWE-202 7.7 High 2026-03-26
CVE-2026-27629 InvenTree Vulnerable to Server Side Template Injection (SSTI) CWE-1336 5.9 Medium 2026-02-25
CVE-2025-49000 InvenTree has uncontrolled memory allocation via built-in label-sheet plugin CWE-400 3.5 Low 2025-06-03
CVE-2024-47610 Stored Cross-site Scripting Vulnerability in Markdown Editor CWE-79 7.3 High 2024-10-07

All 16 known CVE vulnerabilities affecting InvenTree with full Chinese analysis, references, and POCs where available.