Browse all 15 CVE security advisories affecting inventree. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Inventree serves as an open-source inventory management system designed for tracking parts, assemblies, and stock levels. Historically, the platform has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting attacks, and privilege escalation flaws, with 15 CVEs documented to date. Notable security characteristics include its Python/Django architecture and reliance on third-party libraries. While no major public security incidents have been widely reported, the consistent discovery of RCE vulnerabilities in earlier versions highlights potential risks for organizations deploying the system without applying security patches.
This page lists every published CVE security advisory associated with inventree. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.