Vulnerabilities > Inventree Project

DATE CVE VULNERABILITY TITLE RISK
2022-09-29 CVE-2022-3355 Cross-site Scripting vulnerability in Inventree Project Inventree
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3.
network
low complexity
inventree-project CWE-79
5.4
2022-06-20 CVE-2022-2134 Allocation of Resources Without Limits or Throttling vulnerability in Inventree Project Inventree
Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.
network
low complexity
inventree-project CWE-770
6.5
2022-06-17 CVE-2022-2111 Unrestricted Upload of File with Dangerous Type vulnerability in Inventree Project Inventree
Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.
network
low complexity
inventree-project CWE-434
8.8
2022-06-17 CVE-2022-2112 Improper Neutralization of Formula Elements in a CSV File vulnerability in Inventree Project Inventree
Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.
network
low complexity
inventree-project CWE-1236
8.8
2022-06-17 CVE-2022-2113 Cross-site Scripting vulnerability in Inventree Project Inventree
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2.
network
low complexity
inventree-project CWE-79
5.4