« Volver al listado

Inventree Project

Inventree Project Inventree: vulnerabilidades y CVE

Inventree Project Inventree tiene 15 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE15
Últimos 12 meses8
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-39362Media (5.3)0.30%—8 abr 2026
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is enabled (opt-in), authenticated users can supply remote_image URLs that are fetched server-side via…
CVE-2026-35479Media (4.7)0.37%—8 abr 2026
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permissions can install plugins via the API, without requiring "superuser" account access. This level of…
CVE-2026-35478Alta (8.1)0.43%—8 abr 2026
InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token attributed to any other user in the system — including administrators…
CVE-2026-35477Crítica (9.9)0.36%—8 abr 2026
InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to use jinja2.sandbox.SandboxedEnvironment. However, the actual renderer…
CVE-2026-35476Media (4.3)0.24%—8 abr 2026
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The…
CVE-2026-33531Media (4.9)0.38%—26 mar 2026
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report template engine allows a staff-level user to read arbitrary files from the server filesystem…
CVE-2026-33530Media (6.5)0.34%—26 mar 2026
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with bulk data operations can be hijacked to exfiltrate sensitive information from the database. The bulk…
CVE-2026-27629Alta (8.8)0.55%—25 feb 2026
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be hijacked to expose secure information to the client. When generating custom batch codes, the…
CVE-2025-49000Media (5.7)0.33%—3 jun 2025
InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper bound, so a large value forces the server to allocate an enormous…
CVE-2024-47610Media (5.4)0.32%—7 oct 2024
InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for a registered user to store javascript in markdown notes fields, which are then displayed to other logged in…
CVE-2022-3355Media (5.4)0.85%—29 sept 2022
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3.
CVE-2022-2134Media (6.5)0.86%—20 jun 2022
Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.
CVE-2022-2113Media (5.4)0.79%—17 jun 2022
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2.
CVE-2022-2112Alta (8.8)1.3%—17 jun 2022
Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.
CVE-2022-2111Alta (8.8)1.2%—17 jun 2022
Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter2
  2. T1210 Exploitation of Remote Services2
  3. T1078.001 Default Accounts1
  4. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.