Inventree
Vendor:
First CVE: Jun 17, 2022 · Active for 4 years
15
Total CVEs
More Total CVEs than 93% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Inventree over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 17, 2022
4 years ago
Most Recent CVE
Apr 8, 2026
111 days ago
CVE Severity & Scoring
Inventree15 CVEs
60%
33%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (53.3%)
Unknown0 (0.0%)
Required7 (46.7%)
Privileges Required
Low11 (73.3%)
High1 (6.7%)
None3 (20.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35477CRITICAL InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to use jinja2.sandbox.SandboxedEnvi | Apr 8, 2026 | 9.9 | 39 | NO | NO |
CVE-2026-35478HIGH InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token attributed to any other user in | Apr 8, 2026 | 8.1 | 30 | NO | NO |
CVE-2026-27629HIGH InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be hijacked to expose secure information to the client. When gen | Feb 25, 2026 | 8.8 | 29 | NO | NO |
CVE-2022-2111HIGH Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2. | Jun 17, 2022 | 8.8 | 29 | NO | NO |
CVE-2026-39362HIGH InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is enabled (opt-in), authenticated users can supply remote_image | Apr 8, 2026 | 7.1 | 26 | NO | NO |
CVE-2026-33530MEDIUM InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with bulk data operations can be hijacked to exfiltrate sensitive | Mar 26, 2026 | 6.5 | 24 | NO | NO |
CVE-2022-2112HIGH Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2. | Jun 17, 2022 | 8.8 | 24 | NO | NO |
CVE-2026-33531MEDIUM InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report template engine allows a staff-level user to read arbi | Mar 26, 2026 | 6.5 | 22 | NO | NO |
CVE-2022-2134MEDIUM Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0. | Jun 20, 2022 | 6.5 | 22 | NO | NO |
CVE-2026-35479MEDIUM InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permissions can install plugins via the API, without requiring "s | Apr 8, 2026 | 4.7 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Inventree
Top CWEs
Versions
No cataloged versions.