inventree project
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 15 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 17, 2022 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →InvenTree has SSRF via Remote Image Download — No IP/Hostname Validation on remote_image URLs
InvenTree Plugin Installation - Insufficient Permissions
InvenTree Affected by Privilege Escalation via API
InvenTree has Arbitrary API Token Creation
InvenTree has SSTI in PART_NAME_FORMAT bypasses CVE-2026-27629 fix via {% if part.pk %} sandbox escape
InvenTree has Path Traversal In Report Templates
InvenTree Vulnerable to ORM Filter Injection
InvenTree Vulnerable to Server Side Template Injection (SSTI)
InvenTree has uncontrolled memory allocation via built-in label-sheet plugin
Stored Cross-site Scripting Vulnerability in Markdown Editor
Monitor inventree project in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.