VulnSea

InvenTree vulnerabilities

CVEs whose affected-version data names the InvenTree package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

CVE-2026-61748Medium· 4.3
today

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and LabelPrint at POST /api/report/label/print/ require authentication but do not call users.permissions.check_user_permissio…

Sunlitinventree · InvenTreevia NVD
CVE-2026-61747Medium· 4.3
today

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mapping/ endpoints do not scope DataImportRow and DataImportColumnMap querysets to the owner of the associated DataImportSe…

Sunlitinventree · InvenTreevia NVD
CVE-2026-61746Medium· 5.3PoC
today

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginSettingDetail set GlobalSettingsPermissions without the IsAuthenticated permission used by the project default an…

Twilightinventree · InvenTreevia NVD
CVE-2026-61744Medium· 6.5
today

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON barcode containing a lowercase model label and integer primary key, while BarcodeView uses IsAuthen…

Sunlitinventree · InvenTreevia NVD
CVE-2026-61749Medium· 6.5
today

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates can cause WeasyPrint report rendering to retrieve attacker-selected resources through the HTTP and H…

Sunlitinventree · InvenTreevia NVD
CVE-2026-61745Medium· 4.3PoC
today

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in src/backend/InvenTree/machine/api.py uses IsAuthenticatedOrReadScope without requiring the ADMIN role used by other …

Twilightinventree · InvenTreevia NVD
CVE-2022-3355Medium· 5.4
3y ago

Inventree vulnerable to Stored Cross-site Scripting

Inventree vulnerable to Stored Cross-site Scripting

Sunlitinventree · inventreeEPSS 0.68%via OSV
CVE-2022-2112High· 8.8
4y ago

CSV Injection in inventree

CSV Injection in inventree

Twilightinventree · inventreeEPSS 1.3%via OSV
CVE-2022-2111High· 8.8
4y ago

Unrestricted Attachment Upload

Unrestricted Attachment Upload

Twilightinventree · inventreeEPSS 1.2%via OSV
InvenTree vulnerabilities (CVEs) · VulnSea