Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

inventree — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting inventree. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Inventree serves as an open-source inventory management system designed for tracking parts, assemblies, and stock levels. Historically, the platform has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting attacks, and privilege escalation flaws, with 15 CVEs documented to date. Notable security characteristics include its Python/Django architecture and reliance on third-party libraries. While no major public security incidents have been widely reported, the consistent discovery of RCE vulnerabilities in earlier versions highlights potential risks for organizations deploying the system without applying security patches.

Top products by inventree: InvenTree inventree/inventree
CVE ID Title CVSS Severity Published
CVE-2026-61748 InvenTree: Report/Label print endpoints ignore per-model permissions — InvenTree CWE-639 4.3 Medium 2026-09-21
CVE-2026-61746 InvenTree: Plugin-settings GET endpoints are readable without authentication — InvenTree CWE-200 5.3 Medium 2026-09-21
CVE-2026-61744 InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data without enforcing the model's view role — InvenTree CWE-639 6.5 Medium 2026-09-21
CVE-2026-61747 InvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (`row_data`/`data`) and column mappings — InvenTree CWE-639 4.3 Medium 2026-09-21
CVE-2026-61749 InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credential Disclosure — InvenTree CWE-200 6.5 Medium 2026-09-21
CVE-2026-61745 InvenTree: Missing authorization on machine restart endpoint allows any authenticated user to interrupt production equipment — InvenTree CWE-862 4.3 Medium 2026-09-21
CVE-2026-39362 InvenTree has SSRF via Remote Image Download — No IP/Hostname Validation on remote_image URLs — InvenTree CWE-918 7.1AI High AI 2026-04-08
CVE-2026-35479 InvenTree Plugin Installation - Insufficient Permissions — InvenTree CWE-285 6.6 Medium 2026-04-08
CVE-2026-35476 InvenTree Affected by Privilege Escalation via API — InvenTree CWE-285 7.2 High 2026-04-08
CVE-2026-35478 InvenTree has Arbitrary API Token Creation — InvenTree CWE-639 8.3 High 2026-04-08
CVE-2026-35477 InvenTree has SSTI in PART_NAME_FORMAT bypasses CVE-2026-27629 fix via {% if part.pk %} sandbox escape — InvenTree CWE-1336 5.5 Medium 2026-04-08
CVE-2026-33531 InvenTree has Path Traversal In Report Templates — InvenTree CWE-89 4.9 - 2026-03-26
CVE-2026-33530 InvenTree Vulnerable to ORM Filter Injection — InvenTree CWE-202 7.7 High 2026-03-26
CVE-2026-27629 InvenTree Vulnerable to Server Side Template Injection (SSTI) — InvenTree CWE-1336 5.9 Medium 2026-02-25
CVE-2025-49000 InvenTree has uncontrolled memory allocation via built-in label-sheet plugin — InvenTree CWE-400 3.5 Low 2025-06-03
CVE-2024-47610 Stored Cross-site Scripting Vulnerability in Markdown Editor — InvenTree CWE-79 7.3 High 2024-10-07
CVE-2022-3355 Cross-site Scripting (XSS) - Stored in inventree/inventree — inventree/inventree CWE-79 5.4 - 2022-09-29
CVE-2022-2134 Allocation of Resources Without Limits or Throttling in inventree/inventree — inventree/inventree CWE-770 7.5 - 2022-06-20
CVE-2022-2113 Cross-site Scripting (XSS) - Stored in inventree/inventree — inventree/inventree CWE-79 5.4 - 2022-06-17
CVE-2022-2112 Improper Neutralization of Formula Elements in a CSV File in inventree/inventree — inventree/inventree CWE-1236 8.8 - 2022-06-17
CVE-2022-2111 Unrestricted Upload of File with Dangerous Type in inventree/inventree — inventree/inventree CWE-434 8.8 - 2022-06-17

This page lists every published CVE security advisory associated with inventree. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.