inventree_project has 5 CVEs on record. The busiest recent month was April 2026 with 5. The median CVSS is 7.1 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Weakness classes
Products
- inventree 5
Worst active — by depth score
CVE-2026-35478High· 8.3InvenTree is an Open Source Inventory Management System46CVE-2026-35476High· 7.2InvenTree is an Open Source Inventory Management System40CVE-2026-39362High· 7.1InvenTree is an Open Source Inventory Management System39CVE-2026-35479Medium· 6.6InvenTree is an Open Source Inventory Management System36CVE-2026-35477Medium· 5.5InvenTree is an Open Source Inventory Management System30
inventree_project vulnerabilities
CVEs affecting inventree_project, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-39362High· 7.1InvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is enabled (opt-in), authenticated users can supply remote_image URLs that are fetched server-side via requests.get() wit…
CVE-2026-35479Medium· 6.6InvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permissions can install plugins via the API, without requiring "superuser" account access. This level of permission requir…
CVE-2026-35478High· 8.3InvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token attributed to any other user in the system — including administrators and superusers — by…
CVE-2026-35477Medium· 5.5InvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to use jinja2.sandbox.SandboxedEnvironment. However, the actual renderer in part/helpers.py …
CVE-2026-35476High· 7.2InvenTree is an Open Source Inventory Management System
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The write permissions on…