InvenTree vulnerabilities
CVEs whose affected-version data names the InvenTree package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
9 CVEsRSS
CVE-2026-61748Medium· 4.3InvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and LabelPrint at POST /api/report/label/print/ require authentication but do not call users.permissions.check_user_permissio…
CVE-2026-61747Medium· 4.3InvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mapping/ endpoints do not scope DataImportRow and DataImportColumnMap querysets to the owner of the associated DataImportSe…
CVE-2026-61746Medium· 5.3PoCInvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginSettingDetail set GlobalSettingsPermissions without the IsAuthenticated permission used by the project default an…
CVE-2026-61744Medium· 6.5InvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON barcode containing a lowercase model label and integer primary key, while BarcodeView uses IsAuthen…
CVE-2026-61749Medium· 6.5InvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates can cause WeasyPrint report rendering to retrieve attacker-selected resources through the HTTP and H…
CVE-2026-61745Medium· 4.3PoCInvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in src/backend/InvenTree/machine/api.py uses IsAuthenticatedOrReadScope without requiring the ADMIN role used by other …
CVE-2022-3355Medium· 5.4Inventree vulnerable to Stored Cross-site Scripting
Inventree vulnerable to Stored Cross-site Scripting
CVE-2022-2112High· 8.8CSV Injection in inventree
CSV Injection in inventree
CVE-2022-2111High· 8.8Unrestricted Attachment Upload
Unrestricted Attachment Upload