InvenTree

6 known vulnerabilities in InvenTree, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-61749 CVSS 6.5 medium InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates…
  • CVE-2026-61748 CVSS 4.3 medium InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and LabelPrint at POST…
  • CVE-2026-61747 CVSS 4.3 medium InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mapping/ endpoints do…
  • CVE-2026-61746 CVSS 5.3 medium InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginSettingDetail…
  • CVE-2026-61744 CVSS 6.5 medium InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON…
  • CVE-2026-61745 CVSS 4.3 medium InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in…