Company Details
inventory-hive
17
4,391
None
inventoryhive.co.uk
0
INV_9296736
In-progress

Inventory Hive Company CyberSecurity Posture
inventoryhive.co.ukInventory Hive is a beautifully simple cloud-based property reporting and 360° virtual tour software — allowing for market leading paperless creation of inventories, check-ins, interim visits, comparative check-outs, custom reports and 360° virtual tours. Inventory Hive have recently won multiple awards including Best Overall Supplier at the EA Masters 2022, Best Medium Supplier in 2023, and Supplier of the Year (Technology) – Apps at the Negotiator Awards in both 2023 and 2024. Additionally, we were honoured to win the Best Overall Innovation and Improvement Award for Estate Agents at the 2024 EA Masters. Propertymark Industry Supplier. ARL (UKAA) Member NRLA - Preferred Supplier
Company Details
inventory-hive
17
4,391
None
inventoryhive.co.uk
0
INV_9296736
In-progress
Between 750 and 799

Inventory Hive Global Score (TPRM)XXXX

Description: A vulnerability in the website of Inventory Hive, a property inventory service, leaked members’ personal information. It included their name and address, along with internal and external property images. The breach gave access to hundreds of thousands of reports/users' sensitive data across the UK going as back as 2017.


No incidents recorded for Inventory Hive in 2025.
No incidents recorded for Inventory Hive in 2025.
No incidents recorded for Inventory Hive in 2025.
Inventory Hive cyber incidents detection timeline including parent company and subsidiaries

Inventory Hive is a beautifully simple cloud-based property reporting and 360° virtual tour software — allowing for market leading paperless creation of inventories, check-ins, interim visits, comparative check-outs, custom reports and 360° virtual tours. Inventory Hive have recently won multiple awards including Best Overall Supplier at the EA Masters 2022, Best Medium Supplier in 2023, and Supplier of the Year (Technology) – Apps at the Negotiator Awards in both 2023 and 2024. Additionally, we were honoured to win the Best Overall Innovation and Improvement Award for Estate Agents at the 2024 EA Masters. Propertymark Industry Supplier. ARL (UKAA) Member NRLA - Preferred Supplier


City Developments Limited (CDL) is a leading global real estate company with a network spanning 163 locations in 29 countries and regions. Listed on the Singapore Exchange, the Group is one of the largest companies by market capitalisation. Its income-stable and geographically-diverse portfolio comp

SM Prime Holdings, Inc. (SMPH) is one of the largest integrated property developers in Southeast Asia that offers innovative and sustainable lifestyle cities with the development of malls, residences, offices, hotels and convention centers. It is also the largest, in terms of asset, in the Philippin
Welcome to Coldwell Banker Real Estate LLC, a company founded in 1906 on a commitment to professionalism and customer service which remains the cornerstone of our business philosophy today. We are the nation’s oldest real estate company and our experience has helped make the dream of homeownership a

Since 1969, Weichert Realtors has grown from a single office into one of the nation's leading providers of real estate and related services. Their success is rooted in their customer-first philosophy, making every organizational decision based on building trust and sustaining amazing experiences at
We’re a leading professional services firm that specializes in real estate and investment management. JLL shapes the future of real estate for a better world by using the most advanced technology to create rewarding opportunities, amazing spaces and sustainable real estate solutions for our clients,

Anywhere Real Estate Inc. (NYSE: HOUS) is moving the real estate industry to what's next. A leader of integrated residential real estate services, Anywhere includes franchise, brokerage, relocation, and title and settlement businesses, as well as mortgage and title insurance underwriter joint ventur
IWG is leading the workspace revolution. Our companies help more than 2.5 million people and their businesses to work more productively. We do so by providing a choice of professional, inspiring and collaborative workspaces, communities and services. Our customers are start-ups, small and medium-s

Shimao Group has entered the real estate industry since 1989, After more than 30 years of development, the Group has made its layout in more than 100 core development cities across China, involving real estate, commercial, property management, hotel, theme entertainment and culture. Following the n

Savills is a global real estate services provider with a network of more than 40,000 people in over 700 offices across the Americas, Europe, Asia Pacific, Africa and the Middle East. A FTSE 250 company (LON: SVS) headquartered in London, Savills advises corporate, institutional and private clients w
.png)
There is now a greater reliance on digital services for agents, this makes it even more important to review and invest in cybersecurity to...
Inventory Hive bug served up internal and external property images, along with members' contact details.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Inventory Hive is http://www.inventoryhive.co.uk.
According to Rankiteo, Inventory Hive’s AI-generated cybersecurity score is 752, reflecting their Fair security posture.
According to Rankiteo, Inventory Hive currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Inventory Hive is not certified under SOC 2 Type 1.
According to Rankiteo, Inventory Hive does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Inventory Hive is not listed as GDPR compliant.
According to Rankiteo, Inventory Hive does not currently maintain PCI DSS compliance.
According to Rankiteo, Inventory Hive is not compliant with HIPAA regulations.
According to Rankiteo,Inventory Hive is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Inventory Hive operates primarily in the Real Estate industry.
Inventory Hive employs approximately 17 people worldwide.
Inventory Hive presently has no subsidiaries across any sectors.
Inventory Hive’s official LinkedIn profile has approximately 4,391 followers.
Inventory Hive is classified under the NAICS code None, which corresponds to Others.
No, Inventory Hive does not have a profile on Crunchbase.
Yes, Inventory Hive maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/inventory-hive.
As of November 28, 2025, Rankiteo reports that Inventory Hive has experienced 1 cybersecurity incidents.
Inventory Hive has an estimated 29,199 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Vulnerability.
Title: Data Breach at Inventory Hive
Description: A vulnerability in the website of Inventory Hive, a property inventory service, leaked members’ personal information. It included their name and address, along with internal and external property images. The breach gave access to hundreds of thousands of reports/users' sensitive data across the UK going as back as 2017.
Type: Data Breach
Vulnerability Exploited: Website Vulnerability
Common Attack Types: The most common types of attacks the company has faced is Vulnerability.

Data Compromised: Names, Addresses, Internal and external property images
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Addresses, Internal And External Property Images and .

Entity Name: Inventory Hive
Entity Type: Organization
Industry: Property Inventory Service
Location: UK
Customers Affected: Hundreds of thousands

Type of Data Compromised: Names, Addresses, Internal and external property images
Number of Records Exposed: Hundreds of thousands
Sensitivity of Data: High
Most Significant Data Compromised: The most significant data compromised in an incident were Names, Addresses, Internal and External Property Images and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Names, Internal and External Property Images and Addresses.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 0.
.png)
ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.