- EPSS 0.23%
- Veröffentlicht 28.09.2026 21:17:11
- Zuletzt bearbeitet 30.09.2026 19:57:08
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) c...
CVE-2026-100371
- EPSS 0.28%
- Veröffentlicht 28.09.2026 21:17:11
- Zuletzt bearbeitet 30.09.2026 19:57:08
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, an authorization guard to Users::change_password(), was added to address a previous authorization flaw that allowed a secondary admi...
CVE-2026-88003
- EPSS 0.3%
- Veröffentlicht 25.09.2026 21:20:13
- Zuletzt bearbeitet 28.09.2026 15:07:51
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane fails to revoke administrative privileges after a role downgrade because Admin_Controller trusts the user_type snapshot s...
CVE-2026-49850
- EPSS 0.33%
- Veröffentlicht 25.09.2026 15:40:08
- Zuletzt bearbeitet 28.09.2026 15:07:51
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without requiring POST and validat...
CVE-2026-50547
- EPSS 0.47%
- Veröffentlicht 25.09.2026 15:38:31
- Zuletzt bearbeitet 28.09.2026 15:07:51
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Invoices::generate_xml() method appends a database-derived xml_id to the XMLconfigs helper directory and includes the r...
CVE-2026-33639
- EPSS 0.4%
- Veröffentlicht 25.09.2026 15:36:52
- Zuletzt bearbeitet 29.09.2026 20:17:19
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for ip_tax_rates ...
CVE-2026-39353
- EPSS 0.45%
- Veröffentlicht 25.09.2026 15:30:58
- Zuletzt bearbeitet 28.09.2026 15:07:51
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an administrator...
CVE-2026-85293
- EPSS 0.23%
- Veröffentlicht 25.09.2026 15:29:30
- Zuletzt bearbeitet 28.09.2026 15:07:51
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-beta-1, InvoicePlane stores client_email values without enforcing email syntax and renders them unescaped inside double-quoted value ...
CVE-2026-85291
- EPSS 0.26%
- Veröffentlicht 25.09.2026 15:28:33
- Zuletzt bearbeitet 28.09.2026 15:07:51
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Users::change_password() method accepts a user_id from the URL and updates that account's password without an object-le...
CVE-2026-85289
- EPSS 0.17%
- Veröffentlicht 25.09.2026 15:26:22
- Zuletzt bearbeitet 28.09.2026 15:07:51
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane omits ensure_valid_post_request() from delete methods including Payments::delete(), Recurring::delete(), and User_clients...