Inveniosoftware develops a modular digital repository framework with components spanning data management, community features, and content handling across products such as Invenio-App, Invenio-Communities, Invenio-Drafts-Resources, Invenio-Previewer, and Invenio-Records. The observed vulnerability profile centers on application-layer input handling and authorization issues, including cross-site scripting, injection flaws, and missing or incorrect access controls that are characteristic of web-facing data management systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inveniosoftware over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-1020006MEDIUM invenio-app before 1.1.1 allows host header injection. | Jul 29, 2019 | 6.1 | 20 | NO | NO |
CVE-2019-1020019MEDIUM invenio-previewer before 1.0.0a12 allows XSS. | Jul 29, 2019 | 6.1 | 20 | NO | NO |
CVE-2019-1020005MEDIUM invenio-communities before 1.0.0a20 allows XSS. | Jul 29, 2019 | 5.4 | 19 | NO | NO |
CVE-2021-43781MEDIUM Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 | Dec 6, 2021 | 4.3 | 18 | NO | NO |
CVE-2019-1020003MEDIUM invenio-records before 1.2.2 allows XSS. | Jul 29, 2019 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inveniosoftware.
Media articles that mention a CVE ID that affects a product developed by Inveniosoftware — matched by CVE ID, not by vendor name.