CVE-2026-53648
- EPSS 0.26%
- Veröffentlicht 06.07.2026 23:12:09
- Zuletzt bearbeitet 07.07.2026 15:16:48
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product files are stored using a deterministic filename-derived path. When an administrator uploads a file for a downloadable product, FOSSB...
CVE-2026-53647
- EPSS 0.42%
- Veröffentlicht 06.07.2026 23:10:29
- Zuletzt bearbeitet 07.07.2026 15:16:48
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endpoint is accessible without authentication. Any caller with a valid API key can retrieve all custom co...
CVE-2026-53646
- EPSS 0.22%
- Veröffentlicht 06.07.2026 22:58:10
- Zuletzt bearbeitet 07.07.2026 15:16:48
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when a `ClientPasswordReset` record already exists for a client (from a previous unexpired reset request), subsequent calls to the `reset_passwo...
CVE-2026-53645
- EPSS 0.24%
- Veröffentlicht 06.07.2026 22:55:56
- Zuletzt bearbeitet 07.07.2026 14:16:32
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow a low-privileged staff account to grant arbitrary module permissions to itself through the admin API, resulting in persistent privilege escalation....
CVE-2026-53644
- EPSS 0.25%
- Veröffentlicht 06.07.2026 22:51:39
- Zuletzt bearbeitet 07.07.2026 14:16:32
FOSSBilling is a free, open-source billing and client management system. Versions 0.5.3 through 0.7.2 allow authenticated clients to both read and reset API key service secrets for orders that are no longer in an `active` state (e.g., `suspended`, `c...
CVE-2026-53643
- EPSS 0.23%
- Veröffentlicht 06.07.2026 22:49:50
- Zuletzt bearbeitet 07.07.2026 15:16:47
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unauthorized actions via admin API endpoints. The root cause is a combination of the `can_always_access` m...
CVE-2026-53642
- EPSS 0.23%
- Veröffentlicht 06.07.2026 22:45:51
- Zuletzt bearbeitet 07.07.2026 15:16:47
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when the "Require Email Confirmation" setting is enabled, a logged-in client with an unverified email address (`email_approved = 0`) can access ...
CVE-2026-53641
- EPSS 0.29%
- Veröffentlicht 06.07.2026 22:36:38
- Zuletzt bearbeitet 08.07.2026 20:16:52
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a stored cross-site scripting (XSS) vulnerability in the client-facing email history views of FOSSBilling. Email HTML content (`content_html`) ...
CVE-2026-53640
- EPSS 0.23%
- Veröffentlicht 06.07.2026 22:30:48
- Zuletzt bearbeitet 07.07.2026 15:16:47
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff accounts may read sensitive data via admin API endpoints that lack permission checks. While sibling write endpoints correctly enforc...
CVE-2026-43928
- EPSS 0.27%
- Veröffentlicht 06.07.2026 21:53:31
- Zuletzt bearbeitet 07.07.2026 14:16:30
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment adapter accepts PayPal IPN callbacks and credits the IPN-supplied amount (`mc_gross`) to the client's balance without validating ...