📦 Inventree

by Inventree Project

🔍 What is Inventree?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-47610

HIGH CVSS 7.3 Oct 7, 2024

This is a stored cross-site scripting (XSS) vulnerability in InvenTree inventory management system. Registered users can inject malicious JavaScript into markdown notes fields, which then executes in ...

CVE-2022-2111

HIGH CVSS 8.8 Jun 17, 2022

CVE-2022-2111 is an unrestricted file upload vulnerability in InvenTree inventory management software that allows attackers to upload malicious files to the server. This affects all users running Inve...

CVE-2026-27629

MEDIUM CVSS 5.9 Feb 25, 2026

InvenTree versions before 1.2.3 have a server-side template injection vulnerability that allows staff users to modify Jinja2 templates for batch code generation. This can lead to sensitive information...