Invoiceplane

Invoiceplane

29 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.01%
  • Veröffentlicht 18.02.2026 23:03:08
  • Zuletzt bearbeitet 20.02.2026 17:14:02

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A stored cross-site scripting (XSS) vulnerability in the Sumex invoice view allows an authenticated user with client and invoice management privileges...

  • EPSS 0.01%
  • Veröffentlicht 18.02.2026 23:01:41
  • Zuletzt bearbeitet 20.02.2026 17:13:26

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane (latest version) that allows an authenticated user with permissions to manage...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 18.02.2026 22:59:44
  • Zuletzt bearbeitet 20.02.2026 17:07:57

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Product Unit Name fields. An authenticated administrator can in...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 18.02.2026 22:52:27
  • Zuletzt bearbeitet 20.02.2026 17:07:50

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Invoice Number field. An authenticated administrator can inject...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 18.02.2026 22:50:45
  • Zuletzt bearbeitet 20.02.2026 17:07:45

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Family Name field. The `family_name` value is rendered without ...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 18.02.2026 22:49:15
  • Zuletzt bearbeitet 20.02.2026 18:45:32

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7.0 through a chained Local File Inclusion (LFI) and Log Poisoning attac...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 18.02.2026 22:47:19
  • Zuletzt bearbeitet 20.02.2026 18:45:21

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the upload Login Logo functions of InvoicePlane version 1.7.0. In the Upload Login Logo, t...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 18.02.2026 21:01:27
  • Zuletzt bearbeitet 20.02.2026 18:45:14

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the Edit Invoices functions of InvoicePlane version 1.7.0. When editing invoices, the appl...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 18.02.2026 20:59:16
  • Zuletzt bearbeitet 20.02.2026 18:39:46

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the upload Invoice Logo functions of InvoicePlane version 1.7.0. The Upload Invoice Logo f...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 18.02.2026 20:51:20
  • Zuletzt bearbeitet 20.02.2026 18:33:43

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the Edit Quotes functions of InvoicePlane version 1.7.0. In the Editing Quotes function, t...