inventree has 9 CVEs on record between 2022 and 2026. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 5.4 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-639 (3) and CWE-862 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.4
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Worst active — by depth score
CVE-2022-2112High· 8.8CSV Injection in inventree49CVE-2022-2111High· 8.8Unrestricted Attachment Upload49CVE-2026-61746Medium· 5.3InvenTree is an Open Source Inventory Management System41CVE-2026-61749Medium· 6.5InvenTree is an Open Source Inventory Management System36CVE-2026-61745Medium· 4.3InvenTree is an Open Source Inventory Management System36
inventree vulnerabilities
CVEs affecting inventree, newest first. Open any entry for full detail, references, and exploit status.
9 CVEsRSS
CVE-2026-61748Medium· 4.3InvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and LabelPrint at POST /api/report/label/print/ require authentication but do not call users.permissions.check_user_permissio…
CVE-2026-61747Medium· 4.3InvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mapping/ endpoints do not scope DataImportRow and DataImportColumnMap querysets to the owner of the associated DataImportSe…
CVE-2026-61746Medium· 5.3PoCInvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginSettingDetail set GlobalSettingsPermissions without the IsAuthenticated permission used by the project default an…
CVE-2026-61744Medium· 6.5InvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON barcode containing a lowercase model label and integer primary key, while BarcodeView uses IsAuthen…
CVE-2026-61749Medium· 6.5InvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates can cause WeasyPrint report rendering to retrieve attacker-selected resources through the HTTP and H…
CVE-2026-61745Medium· 4.3PoCInvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in src/backend/InvenTree/machine/api.py uses IsAuthenticatedOrReadScope without requiring the ADMIN role used by other …
CVE-2022-3355Medium· 5.4Inventree vulnerable to Stored Cross-site Scripting
Inventree vulnerable to Stored Cross-site Scripting
CVE-2022-2112High· 8.8CSV Injection in inventree
CSV Injection in inventree
CVE-2022-2111High· 8.8Unrestricted Attachment Upload
Unrestricted Attachment Upload