CVE-2022-3355Medium· 5.4▾ SunlitInventree vulnerable to Stored Cross-site Scripting
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
0.6% → 0.7%
Inventree prior to 0.8.3 is vulnerable to stored cross-site scripting by uploading SVG files. Version 0.8.3 contains a patch for this issue.
inventree < 0.8.3Upgrade to a patched release:
inventree 0.8.3Connected by shared product, vendor, weakness, or advisory.
CVE-2022-2111High· 8.8Unrestricted Attachment Upload
CVE-2022-2112High· 8.8CSV Injection in inventree
CVE-2026-61748Medium· 4.3InvenTree is an Open Source Inventory Management System
CVE-2026-61746Medium· 5.3InvenTree is an Open Source Inventory Management System
CVE-2026-61747Medium· 4.3InvenTree is an Open Source Inventory Management System
CVE-2026-61744Medium· 6.5InvenTree is an Open Source Inventory Management System