Inventree Project maintains an open-source inventory management and parts-tracking application that, despite a narrow product scope, occupies a prominent role in electronics engineering and manufacturing workflows. The application's recurring vulnerability patterns center on web-layer input handling and authorization logic—cross-site scripting, template injection, resource-exhaustion conditions, and authorization bypass—reflecting the complexity of user-driven data processing and access control in multi-tenant inventory systems. A meaningful share of the vendor's disclosures reach serious severity; live exploitation status, current counts, and severity breakdown are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inventree Project over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35477CRITICAL InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to use jinja2.sandbox.SandboxedEnvi | Apr 8, 2026 | 9.9 | 39 | NO | NO |
CVE-2026-35478HIGH InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token attributed to any other user in | Apr 8, 2026 | 8.1 | 30 | NO | NO |
CVE-2026-27629HIGH InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be hijacked to expose secure information to the client. When gen | Feb 25, 2026 | 8.8 | 29 | NO | NO |
CVE-2022-2111HIGH Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2. | Jun 17, 2022 | 8.8 | 29 | NO | NO |
CVE-2026-39362HIGH InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is enabled (opt-in), authenticated users can supply remote_image | Apr 8, 2026 | 7.1 | 26 | NO | NO |
CVE-2026-33530MEDIUM InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with bulk data operations can be hijacked to exfiltrate sensitive | Mar 26, 2026 | 6.5 | 24 | NO | NO |
CVE-2022-2112HIGH Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2. | Jun 17, 2022 | 8.8 | 24 | NO | NO |
CVE-2026-33531MEDIUM InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report template engine allows a staff-level user to read arbi | Mar 26, 2026 | 6.5 | 22 | NO | NO |
CVE-2022-2134MEDIUM Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0. | Jun 20, 2022 | 6.5 | 22 | NO | NO |
CVE-2026-35479MEDIUM InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permissions can install plugins via the API, without requiring "s | Apr 8, 2026 | 4.7 | 21 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inventree Project.
Media articles that mention a CVE ID that affects a product developed by Inventree Project — matched by CVE ID, not by vendor name.