InvenTree
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 13 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 7, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →InvenTree: Report/Label print endpoints ignore per-model permissions
InvenTree: Plugin-settings GET endpoints are readable without authentication
InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data without enforcing the model's view role
InvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (`row_data`/`data`) and column mappings
InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credential Disclosure
InvenTree: Missing authorization on machine restart endpoint allows any authenticated user to interrupt production equipment
InvenTree Plugin Installation - Insufficient Permissions
InvenTree has Arbitrary API Token Creation
InvenTree has SSTI in PART_NAME_FORMAT bypasses CVE-2026-27629 fix via {% if part.pk %} sandbox escape
InvenTree has Path Traversal In Report Templates
Monitor InvenTree in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.