Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.48%—InventreeAIKozea WeasyprintAI21/9/202624/9/2026
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates can cause WeasyPrint report rendering to retrieve attacker-selected resources through the HTTP and HTTPS URL schemes or the local file URI scheme. The HTML(string=html).write_pdf()…
AplazadaMedia (4.3)0.42%—InventreeAI21/9/202624/9/2026
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and LabelPrint at POST /api/report/label/print/ require authentication but do not call users.permissions.check_user_permission for the caller's per-model view role before selecting objects by primary key and…
AplazadaMedia (4.3)0.34%—InventreeAI21/9/202623/9/2026
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mapping/ endpoints do not scope DataImportRow and DataImportColumnMap querysets to the owner of the associated DataImportSession. Any authenticated user, including an account with no assigned roles, can…
AplazadaMedia (5.3)0.40%—InventreeAI21/9/202623/9/2026
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginSettingDetail set GlobalSettingsPermissions without the IsAuthenticated permission used by the project default and equivalent global-settings endpoints. GlobalSettingsPermissions returns true for…
AplazadaMedia (6.5)0.51%—InventreeAI21/9/202629/9/2026
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON barcode containing a lowercase model label and integer primary key, while BarcodeView uses IsAuthenticatedOrReadScope and requires only authentication or a general read scope. The…
AplazadaMedia (4.3)0.43%—InventreeAI21/9/202623/9/2026
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in src/backend/InvenTree/machine/api.py uses IsAuthenticatedOrReadScope without requiring the ADMIN role used by other machine management operations. Any authenticated user who lacks the ADMIN role,…
AnalizadaMedia (5.3)0.30%—Inventree Project Inventree8/4/202624/7/2026
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is enabled (opt-in), authenticated users can supply remote_image URLs that are fetched server-side via requests.get() with only Django's URLValidator check. There is no validation against private IP…
AnalizadaMedia (4.7)0.37%—Inventree Project Inventree8/4/202624/7/2026
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permissions can install plugins via the API, without requiring "superuser" account access. This level of permission requirement is out of alignment with other plugin actions (such as uninstalling) which…
AnalizadaAlta (8.1)0.43%—Inventree Project Inventree8/4/202624/7/2026
InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token attributed to any other user in the system — including administrators and superusers — by supplying the target's user ID in the user field of a POST /api/user/tokens/…
AnalizadaCrítica (9.9)0.36%—Inventree Project Inventree8/4/202624/7/2026
InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to use jinja2.sandbox.SandboxedEnvironment. However, the actual renderer in part/helpers.py was not updated and still uses the non-sandboxed jinja2.Environment. Additionally,…
AnalizadaMedia (4.3)0.24%—Inventree Project Inventree8/4/202624/7/2026
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The write permissions on the API endpoint are improperly configured, allowing any user to change their…
AnalizadaMedia (4.9)0.38%—Inventree Project Inventree26/3/202617/6/2026
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report template engine allows a staff-level user to read arbitrary files from the server filesystem via crafted template tags. Affected functions: `encode_svg_image()`, `asset()`, and…
AnalizadaMedia (6.5)0.34%—Inventree Project Inventree26/3/202617/6/2026
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with bulk data operations can be hijacked to exfiltrate sensitive information from the database. The bulk operation API endpoints (e.g. `/api/part/`, `/api/stock/`, `/api/order/so/allocation/`, and others)…
AnalizadaAlta (8.8)0.55%—Inventree Project Inventree25/2/202617/6/2026
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be hijacked to expose secure information to the client. When generating custom batch codes, the InvenTree server makes use of a customizable jinja2 template, which can be modified by a staff user to…
AnalizadaMedia (5.7)0.33%—Inventree Project Inventree3/6/202517/6/2026
InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper bound, so a large value forces the server to allocate an enormous Python list. This lets any authenticated label-printing user trigger a denial-of-service via memory…
AnalizadaMedia (5.4)0.32%—Inventree Project Inventree7/10/202417/6/2026
InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for a registered user to store javascript in markdown notes fields, which are then displayed to other logged in users who visit the same page and executed. The vulnerability has been addressed as follows: 1. HTML…
ModificadaMedia (5.4)0.85%—Inventree Project Inventree29/9/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3.
ModificadaMedia (6.5)0.86%—Inventree Project Inventree20/6/202217/6/2026
Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.
ModificadaMedia (5.4)0.79%—Inventree Project Inventree17/6/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2.
ModificadaAlta (8.8)1.3%—Inventree Project Inventree17/6/202217/6/2026
Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.
ModificadaAlta (8.8)1.2%—Inventree Project Inventree17/6/202217/6/2026
Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.