Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.48% | — | InventreeAIKozea WeasyprintAI | 21/9/2026 | 24/9/2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates can cause WeasyPrint report rendering to retrieve attacker-selected resources through the HTTP and HTTPS URL schemes or the local file URI scheme. The HTML(string=html).write_pdf()… | |
| Aplazada | Media (4.3) | 0.42% | — | InventreeAI | 21/9/2026 | 24/9/2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and LabelPrint at POST /api/report/label/print/ require authentication but do not call users.permissions.check_user_permission for the caller's per-model view role before selecting objects by primary key and… | |
| Aplazada | Media (4.3) | 0.34% | — | InventreeAI | 21/9/2026 | 23/9/2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mapping/ endpoints do not scope DataImportRow and DataImportColumnMap querysets to the owner of the associated DataImportSession. Any authenticated user, including an account with no assigned roles, can… | |
| Aplazada | Media (5.3) | 0.40% | — | InventreeAI | 21/9/2026 | 23/9/2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginSettingDetail set GlobalSettingsPermissions without the IsAuthenticated permission used by the project default and equivalent global-settings endpoints. GlobalSettingsPermissions returns true for… | |
| Aplazada | Media (6.5) | 0.51% | — | InventreeAI | 21/9/2026 | 29/9/2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON barcode containing a lowercase model label and integer primary key, while BarcodeView uses IsAuthenticatedOrReadScope and requires only authentication or a general read scope. The… | |
| Aplazada | Media (4.3) | 0.43% | — | InventreeAI | 21/9/2026 | 23/9/2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in src/backend/InvenTree/machine/api.py uses IsAuthenticatedOrReadScope without requiring the ADMIN role used by other machine management operations. Any authenticated user who lacks the ADMIN role,… | |
| Analizada | Media (5.3) | 0.30% | — | Inventree Project Inventree | 8/4/2026 | 24/7/2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is enabled (opt-in), authenticated users can supply remote_image URLs that are fetched server-side via requests.get() with only Django's URLValidator check. There is no validation against private IP… | |
| Analizada | Media (4.7) | 0.37% | — | Inventree Project Inventree | 8/4/2026 | 24/7/2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permissions can install plugins via the API, without requiring "superuser" account access. This level of permission requirement is out of alignment with other plugin actions (such as uninstalling) which… | |
| Analizada | Alta (8.1) | 0.43% | — | Inventree Project Inventree | 8/4/2026 | 24/7/2026 | InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token attributed to any other user in the system — including administrators and superusers — by supplying the target's user ID in the user field of a POST /api/user/tokens/… | |
| Analizada | Crítica (9.9) | 0.36% | — | Inventree Project Inventree | 8/4/2026 | 24/7/2026 | InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to use jinja2.sandbox.SandboxedEnvironment. However, the actual renderer in part/helpers.py was not updated and still uses the non-sandboxed jinja2.Environment. Additionally,… | |
| Analizada | Media (4.3) | 0.24% | — | Inventree Project Inventree | 8/4/2026 | 24/7/2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The write permissions on the API endpoint are improperly configured, allowing any user to change their… | |
| Analizada | Media (4.9) | 0.38% | — | Inventree Project Inventree | 26/3/2026 | 17/6/2026 | InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report template engine allows a staff-level user to read arbitrary files from the server filesystem via crafted template tags. Affected functions: `encode_svg_image()`, `asset()`, and… | |
| Analizada | Media (6.5) | 0.34% | — | Inventree Project Inventree | 26/3/2026 | 17/6/2026 | InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with bulk data operations can be hijacked to exfiltrate sensitive information from the database. The bulk operation API endpoints (e.g. `/api/part/`, `/api/stock/`, `/api/order/so/allocation/`, and others)… | |
| Analizada | Alta (8.8) | 0.55% | — | Inventree Project Inventree | 25/2/2026 | 17/6/2026 | InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be hijacked to expose secure information to the client. When generating custom batch codes, the InvenTree server makes use of a customizable jinja2 template, which can be modified by a staff user to… | |
| Analizada | Media (5.7) | 0.33% | — | Inventree Project Inventree | 3/6/2025 | 17/6/2026 | InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper bound, so a large value forces the server to allocate an enormous Python list. This lets any authenticated label-printing user trigger a denial-of-service via memory… | |
| Analizada | Media (5.4) | 0.32% | — | Inventree Project Inventree | 7/10/2024 | 17/6/2026 | InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for a registered user to store javascript in markdown notes fields, which are then displayed to other logged in users who visit the same page and executed. The vulnerability has been addressed as follows: 1. HTML… | |
| Modificada | Media (5.4) | 0.85% | — | Inventree Project Inventree | 29/9/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3. | |
| Modificada | Media (6.5) | 0.86% | — | Inventree Project Inventree | 20/6/2022 | 17/6/2026 | Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0. | |
| Modificada | Media (5.4) | 0.79% | — | Inventree Project Inventree | 17/6/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2. | |
| Modificada | Alta (8.8) | 1.3% | — | Inventree Project Inventree | 17/6/2022 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2. | |
| Modificada | Alta (8.8) | 1.2% | — | Inventree Project Inventree | 17/6/2022 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2. |