Vulnerabilidades en inventree

21 resultados
Análisis Vexday

A InvenTree apresenta 15 vulnerabilidades catalogadas, sendo 2 críticas, sem registros de exploração ativa no ambiente observado. A fraqueza dominante é cross-site scripting (CWE-79), típica de aplicações web, e não há vulnerabilidades recentes que sinalizem intensificação do risco nos últimos 90 dias.

CVE-2022-2112CRITICALImproper Neutralization of Formula Elements in a CSV File in inventree/inventreeEPSS 1.3%CVE-2022-2111CRITICALUnrestricted Upload of File with Dangerous Type in inventree/inventreeEPSS 1.2%CVE-2022-2134HIGHAllocation of Resources Without Limits or Throttling in inventree/inventreeEPSS 0.9%CVE-2022-2113HIGHCross-site Scripting (XSS) - Stored in inventree/inventreeEPSS 0.8%CVE-2022-3355HIGHCross-site Scripting (XSS) - Stored in inventree/inventreeEPSS 0.7%CVE-2026-27629MEDIUMInvenTree Vulnerable to Server Side Template Injection (SSTI)EPSS 0.5%CVE-2026-61744MEDIUMInvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data without enforcing the model's view roleEPSS 0.5%CVE-2026-61749MEDIUMInvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credential DisclosureEPSS 0.5%CVE-2026-35478HIGHInvenTree has Arbitrary API Token CreationEPSS 0.4%CVE-2026-61745MEDIUMInvenTree: Missing authorization on machine restart endpoint allows any authenticated user to interrupt production equipmentEPSS 0.4%CVE-2026-61748MEDIUMInvenTree: Report/Label print endpoints ignore per-model permissionsEPSS 0.4%CVE-2026-61746MEDIUMInvenTree: Plugin-settings GET endpoints are readable without authenticationEPSS 0.4%CVE-2026-33531MEDIUMInvenTree has Path Traversal In Report TemplatesEPSS 0.4%CVE-2026-35479MEDIUMInvenTree Plugin Installation - Insufficient PermissionsEPSS 0.4%CVE-2026-35477MEDIUMInvenTree has SSTI in PART_NAME_FORMAT bypasses CVE-2026-27629 fix via {% if part.pk %} sandbox escapeEPSS 0.4%CVE-2026-61747MEDIUMInvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (`row_data`/`data`) and column mappingsEPSS 0.3%CVE-2026-33530HIGHInvenTree Vulnerable to ORM Filter InjectionEPSS 0.3%CVE-2025-49000LOWInvenTree has uncontrolled memory allocation via built-in label-sheet pluginEPSS 0.3%CVE-2024-47610HIGHStored Cross-site Scripting Vulnerability in Markdown EditorEPSS 0.3%CVE-2026-39362MEDIUMInvenTree has SSRF via Remote Image Download — No IP/Hostname Validation on remote_image URLsEPSS 0.3%