CVE-2026-61688
- EPSS 0.26%
- Veröffentlicht 04.09.2026 17:49:08
- Zuletzt bearbeitet 10.09.2026 15:13:07
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the same company by manipulating two writable Symfony UX LiveComponent props on th...
CVE-2026-61614
- EPSS 0.28%
- Veröffentlicht 04.09.2026 17:48:16
- Zuletzt bearbeitet 10.09.2026 15:13:07
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallback to the `X-API-TOKEN` header. This causes long-lived API credentials to be re...
CVE-2026-61608
- EPSS 0.24%
- Veröffentlicht 04.09.2026 17:46:42
- Zuletzt bearbeitet 10.09.2026 15:13:07
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning a leaked, forwarded, or archived invitation email can b...
CVE-2026-61686
- EPSS 0.42%
- Veröffentlicht 04.09.2026 17:43:56
- Zuletzt bearbeitet 10.09.2026 15:13:07
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`, a...
CVE-2026-46489
- EPSS 0.31%
- Veröffentlicht 11.06.2026 18:55:44
- Zuletzt bearbeitet 12.06.2026 11:16:22
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can upload an SVG file containing embedded JavaScript. This script is...
CVE-2026-46622
- EPSS 0.2%
- Veröffentlicht 11.06.2026 18:55:23
- Zuletzt bearbeitet 15.06.2026 21:17:10
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the database —...
CVE-2025-55579
- EPSS 0.26%
- Veröffentlicht 29.08.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 14:00:39
SolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. The vulnerability is fixed in version 2.3.8.
CVE-2025-55580
- EPSS 0.26%
- Veröffentlicht 29.08.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 14:00:05
SolidInvoice version 2.3.7 is vulnerable to a stored cross-site scripting (XSS) issue in the Clients module. An authenticated attacker can inject JavaScript that executes in other users' browsers when the Clients page is viewed. The vulnerability is ...
CVE-2025-9171
- EPSS 0.29%
- Veröffentlicht 19.08.2025 22:32:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component Clients Module. Performing manipulation of the argument Name results in cross site scripting. The attac...
CVE-2025-9170
- EPSS 0.29%
- Veröffentlicht 19.08.2025 22:15:28
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was identified in SolidInvoice up to 2.4.0. The affected element is an unknown function of the file /tax/rates of the component Tax Rates Module. Such manipulation of the argument Name leads to cross site scripting. The attack can be ...