CVE-2022-2112High· 8.8▾ TwilightCSV Injection in inventree
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.2%
1.2% → 1.3%
Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.
inventree < 0.7.2Upgrade to a patched release:
inventree 0.7.2Connected by shared product, vendor, weakness, or advisory.
CVE-2022-2111High· 8.8Unrestricted Attachment Upload
CVE-2022-3355Medium· 5.4Inventree vulnerable to Stored Cross-site Scripting
CVE-2026-61748Medium· 4.3InvenTree is an Open Source Inventory Management System
CVE-2026-61746Medium· 5.3InvenTree is an Open Source Inventory Management System
CVE-2026-61747Medium· 4.3InvenTree is an Open Source Inventory Management System
CVE-2026-61744Medium· 6.5InvenTree is an Open Source Inventory Management System