CVE-2026-43927
- EPSS 0.22%
- Veröffentlicht 06.07.2026 21:49:26
- Zuletzt bearbeitet 07.07.2026 13:22:13
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, a race condition in the cart checkout flow allows an authenticated client to apply a promo code beyond its configured maximum uses. By sending concurrent...
CVE-2026-43925
- EPSS 0.3%
- Veröffentlicht 06.07.2026 21:41:00
- Zuletzt bearbeitet 07.07.2026 15:16:47
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in the client self-registration endpoint allows any visitor to assign themselves to an arbitrary client ...
CVE-2026-43921
- EPSS 0.27%
- Veröffentlicht 06.07.2026 21:38:49
- Zuletzt bearbeitet 07.07.2026 15:16:47
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code injection vulnerability in FOSSBilling's `Config::prettyPrintArrayToPHP()` method. When configuration values are updated, string va...
CVE-2026-43918
- EPSS 0.24%
- Veröffentlicht 06.07.2026 21:18:31
- Zuletzt bearbeitet 08.07.2026 20:16:49
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/admin account is suspended or marked inactive, existing authenticated sessions are not invalidated. The session identity loaders i...
CVE-2026-42331
- EPSS 0.25%
- Veröffentlicht 06.07.2026 21:00:07
- Zuletzt bearbeitet 07.07.2026 15:16:46
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an authorization check present in other invoice-related endpoints, allowing an unauthenticated user with...
CVE-2026-33734
- EPSS 0.22%
- Veröffentlicht 06.07.2026 20:56:26
- Zuletzt bearbeitet 07.07.2026 15:16:43
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injection vulnerability in the `Massmailer` module filter functionality. An authenticated administrator can supply crafted filter values ...
CVE-2026-42341
- EPSS 0.18%
- Veröffentlicht 06.07.2026 20:53:21
- Zuletzt bearbeitet 07.07.2026 16:16:39
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker...
CVE-2026-43920
- EPSS 0.55%
- Veröffentlicht 25.06.2026 23:06:43
- Zuletzt bearbeitet 26.06.2026 16:10:29
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was accessible without authentication, which allowed unauthenticated remote users to trigge...
CVE-2026-33543
- EPSS 0.29%
- Veröffentlicht 24.06.2026 21:16:53
- Zuletzt bearbeitet 25.06.2026 19:58:30
FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API endpoint, /api/guest/staff/create, intended for initial administrator bootstrap. Due to a flawed admin-existence check, the endpoint ...
CVE-2026-27708
- EPSS 0.27%
- Veröffentlicht 24.06.2026 19:24:50
- Zuletzt bearbeitet 25.06.2026 20:17:10
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method accepts an order_id parameter and fetches the associated order without verifying the authenticated clie...