VendorsInvenTree Projectinventreeall versions
Vulnerabilities

InvenTree Project InvenTree

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-35477
InvenTree has SSTI in PART_NAME_FORMAT bypasses CVE-2026-27629 fix via {% if part.pk %} sandbox escape
Published 2026-04-08 · Analyzed
9.9EPSS 0.004
CVE-2022-2112
Improper Neutralization of Formula Elements in a CSV File in inventree/inventree
Published 2022-06-17 · Modified
9.0EPSS 0.013
CVE-2022-2111
Unrestricted Upload of File with Dangerous Type in inventree/inventree
Published 2022-06-17 · Modified
9.0EPSS 0.012
CVE-2026-27629
InvenTree Vulnerable to Server Side Template Injection (SSTI)
Published 2026-02-25 · Analyzed
8.8EPSS 0.005
CVE-2022-2113
Cross-site Scripting (XSS) - Stored in inventree/inventree
Published 2022-06-17 · Modified
8.4EPSS 0.008
CVE-2026-35478
InvenTree has Arbitrary API Token Creation
Published 2026-04-08 · Analyzed
8.3EPSS 0.004
CVE-2022-3355
Cross-site Scripting (XSS) - Stored in inventree/inventree
Published 2022-09-29 · Modified
8.2EPSS 0.007
CVE-2026-33530
InvenTree Vulnerable to ORM Filter Injection
Published 2026-03-26 · Analyzed
7.7EPSS 0.003
CVE-2024-47610
Stored Cross-site Scripting Vulnerability in Markdown Editor
Published 2024-10-07 · Analyzed
7.3EPSS 0.003
CVE-2026-35476
InvenTree Affected by Privilege Escalation via API
Published 2026-04-08 · Analyzed
7.2EPSS 0.002
CVE-2022-2134
Allocation of Resources Without Limits or Throttling in inventree/inventree
Published 2022-06-20 · Modified
7.1EPSS 0.009
CVE-2026-39362
InvenTree has SSRF via Remote Image Download — No IP/Hostname Validation on remote_image URLs
Published 2026-04-08 · Analyzed
7.1EPSS 0.003
CVE-2026-35479
InvenTree Plugin Installation - Insufficient Permissions
Published 2026-04-08 · Analyzed
6.6EPSS 0.004
CVE-2026-33531
InvenTree has Path Traversal In Report Templates
Published 2026-03-26 · Analyzed
6.5EPSS 0.004
CVE-2025-49000
InvenTree has uncontrolled memory allocation via built-in label-sheet plugin
Published 2025-06-03 · Analyzed
5.7EPSS 0.003