CVE Tools

Inventory System

9 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Inventory System, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Inventory System CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Inventory System CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-035
2026-040
2026-050
2026-063
2026-070
2026-080
2026-090

Severity

How the 9 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Medium889%
  • Low111%

Latest CVEs

The 9 most recently published vulnerabilities affecting Inventory System.

  1. CVE-2026-11520SourceCodester Inventory System header.php cross site scripting3.5
  2. CVE-2026-11519SourceCodester Inventory System Account Creation users_handler.php improper authorization6.3
  3. CVE-2026-11518SourceCodester Inventory System User Management users.php cross site scripting4.3
  4. CVE-2026-30570A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_sales.php file via the "limit" parameter. The application fails to sanitize ...6.1
  5. CVE-2026-30571A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_category.php file via the "limit" parameter. The application fails to saniti...6.1
  6. CVE-2026-30569A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_stock_availability.php file via the "limit" pa...6.1
  7. CVE-2026-30567A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_product.php file via the "limit" parameter. The application fails to sanitiz...6.1
  8. CVE-2026-30568A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in in the view_purchase.php file via the "limit" parameter. The application fails to san...4.8
  9. CVE-2023-23014Cross Site Scripting (XSS) vulnerability in InventorySystem thru commit e08fbbe17902146313501ed0b5feba81d58f455c (on Apr 23, 2021) via edit_store_name and edit_active inputs in file InventorySystem...6.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store