CVE-2026-39362
- EPSS 0.04%
- Veröffentlicht 08.04.2026 19:32:46
- Zuletzt bearbeitet 21.04.2026 13:34:53
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is enabled (opt-in), authenticated users can supply remote_image URLs that are fetched server-side via requests.get() with only Django...
CVE-2026-35479
- EPSS 0.03%
- Veröffentlicht 08.04.2026 19:27:57
- Zuletzt bearbeitet 21.04.2026 13:35:16
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permissions can install plugins via the API, without requiring "superuser" account access. This level of permission requirement is out ...
CVE-2026-35476
- EPSS 0.03%
- Veröffentlicht 08.04.2026 19:26:12
- Zuletzt bearbeitet 21.04.2026 13:34:40
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The write permissions on the API endp...
CVE-2026-35478
- EPSS 0.07%
- Veröffentlicht 08.04.2026 19:24:05
- Zuletzt bearbeitet 20.04.2026 15:12:03
InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token attributed to any other user in the system — including administrators and superusers — by supplying th...
CVE-2026-35477
- EPSS 0.02%
- Veröffentlicht 08.04.2026 19:20:58
- Zuletzt bearbeitet 20.04.2026 15:14:39
InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to use jinja2.sandbox.SandboxedEnvironment. However, the actual renderer in part/helpers.py was not updat...
CVE-2026-33531
- EPSS 0.04%
- Veröffentlicht 26.03.2026 19:40:50
- Zuletzt bearbeitet 01.04.2026 18:50:41
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report template engine allows a staff-level user to read arbitrary files from the server filesystem via crafted template tags. Affe...
CVE-2026-33530
- EPSS 0.03%
- Veröffentlicht 26.03.2026 19:34:51
- Zuletzt bearbeitet 01.04.2026 18:48:48
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with bulk data operations can be hijacked to exfiltrate sensitive information from the database. The bulk operation API endpoints (e.g. ...
CVE-2026-27629
- EPSS 0.13%
- Veröffentlicht 25.02.2026 03:16:06
- Zuletzt bearbeitet 27.02.2026 20:00:51
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be hijacked to expose secure information to the client. When generating custom batch codes, the InvenTree server makes use of a custom...
CVE-2025-49000
- EPSS 0.19%
- Veröffentlicht 03.06.2025 20:54:27
- Zuletzt bearbeitet 17.12.2025 15:10:49
InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper bound, so a large value forces the server to allocate an enormous Python list. This lets any authent...
CVE-2024-47610
- EPSS 0.64%
- Veröffentlicht 07.10.2024 21:15:18
- Zuletzt bearbeitet 17.12.2025 15:09:55
InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for a registered user to store javascript in markdown notes fields, which are then displayed to other logged in users who visit the same page an...