{"api_version":"v1","generated_at":"2026-10-08T23:50:00+00:00","product":{"cve_count":16,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-inventree-inventree-c6870b14781e","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"InvenTree","next_cursor":null,"observations":[{"affected":"InvenTree: < 1.4.0","affected_versions_present":true,"cve_id":"CVE-2026-61748","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-61748","fixed":"1.4.0.","last_modified":"2026-09-24T22:30:22.380Z","patch_url":"https://github.com/inventree/InvenTree/security/advisories/GHSA-7w96-99fj-8g7x","primary_source":"","published":"2026-09-21T18:47:14.044Z"},{"affected":"InvenTree: < 1.4.0","affected_versions_present":true,"cve_id":"CVE-2026-61746","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-61746","fixed":"1.4.0.","last_modified":"2026-09-21T19:06:42.269Z","patch_url":"https://github.com/inventree/InvenTree/security/advisories/GHSA-45f6-v6jq-99f7","primary_source":"","published":"2026-09-21T18:46:25.292Z"},{"affected":"InvenTree: < 1.4.0","affected_versions_present":true,"cve_id":"CVE-2026-61744","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-61744","fixed":"1.4.0.","last_modified":"2026-09-29T15:07:12.160Z","patch_url":"https://github.com/inventree/InvenTree/security/advisories/GHSA-6pm3-m334-mr4j","primary_source":"","published":"2026-09-21T18:45:38.373Z"},{"affected":"InvenTree: < 1.4.0","affected_versions_present":true,"cve_id":"CVE-2026-61747","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-61747","fixed":"1.4.0.","last_modified":"2026-09-21T20:05:00.096Z","patch_url":"https://github.com/inventree/InvenTree/security/advisories/GHSA-xjpv-cwpw-7qx8","primary_source":"","published":"2026-09-21T18:44:15.662Z"},{"affected":"InvenTree: < 1.4.0","affected_versions_present":true,"cve_id":"CVE-2026-61749","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-61749","fixed":"1.4.0.","last_modified":"2026-09-24T22:29:20.432Z","patch_url":"https://github.com/inventree/InvenTree/security/advisories/GHSA-568x-qh23-wh8g","primary_source":"","published":"2026-09-21T18:31:54.532Z"},{"affected":"InvenTree: < 1.4.0","affected_versions_present":true,"cve_id":"CVE-2026-61745","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-61745","fixed":"1.4.0.","last_modified":"2026-09-21T18:35:40.123Z","patch_url":"https://github.com/inventree/InvenTree/security/advisories/GHSA-c9wp-mw98-gfrj","primary_source":"","published":"2026-09-21T17:52:39.111Z"},{"affected":"InvenTree: < 1.2.7","affected_versions_present":true,"cve_id":"CVE-2026-39362","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39362","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-10T20:44:13.278Z","patch_url":"","primary_source":"","published":"2026-04-08T19:32:46.744Z"},{"affected":"InvenTree: < 1.2.7","affected_versions_present":true,"cve_id":"CVE-2026-35479","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35479","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-09T14:16:36.423Z","patch_url":"","primary_source":"","published":"2026-04-08T19:27:57.320Z"},{"affected":"InvenTree: < 1.2.7","affected_versions_present":true,"cve_id":"CVE-2026-35476","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35476","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-08T19:53:28.982Z","patch_url":"","primary_source":"","published":"2026-04-08T19:26:12.692Z"},{"affected":"InvenTree: >= 0.16.0, < 1.2.7","affected_versions_present":true,"cve_id":"CVE-2026-35478","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35478","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-08T20:12:15.181Z","patch_url":"","primary_source":"","published":"2026-04-08T19:24:05.044Z"},{"affected":"InvenTree: >= 1.2.3, < 1.2.7","affected_versions_present":true,"cve_id":"CVE-2026-35477","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35477","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-10T20:43:12.243Z","patch_url":"","primary_source":"","published":"2026-04-08T19:20:58.967Z"},{"affected":"InvenTree: < 1.2.6","affected_versions_present":true,"cve_id":"CVE-2026-33531","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33531","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-27T19:47:03.887Z","patch_url":"https://github.com/inventree/InvenTree/pull/11579","primary_source":"","published":"2026-03-26T19:40:50.787Z"},{"affected":"InvenTree: < 1.2.6","affected_versions_present":true,"cve_id":"CVE-2026-33530","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33530","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-30T11:24:37.542Z","patch_url":"https://github.com/inventree/InvenTree/pull/11581","primary_source":"","published":"2026-03-26T19:34:51.294Z"},{"affected":"< 1.2.3","affected_versions_present":true,"cve_id":"CVE-2026-27629","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27629","fixed":"1.2.3","last_modified":"2026-02-26T21:33:40.971Z","patch_url":"https://github.com/inventree/InvenTree/security/advisories/GHSA-cx85-vr3q-9x4m","primary_source":"","published":"2026-02-25T02:48:41.934Z"},{"affected":"< 0.17.13","affected_versions_present":true,"cve_id":"CVE-2025-49000","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-49000","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-04T13:49:33.402Z","patch_url":"https://github.com/inventree/InvenTree/commit/0826a75ef6dde0ad96d680f52a9cf171ba2ce98b","primary_source":"","published":"2025-06-03T20:54:27.744Z"},{"affected":"< 0.16.5","affected_versions_present":true,"cve_id":"CVE-2024-47610","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-47610","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-10-08T14:20:43.155Z","patch_url":"https://github.com/inventree/InvenTree/commit/6e37f0cd8ba5fc527412f18f66cd6a37015fa690","primary_source":"","published":"2024-10-07T20:45:20.510Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"inventree"}}
