CVE-2026-85292
- EPSS 0.25%
- Veröffentlicht 25.09.2026 15:25:26
- Zuletzt bearbeitet 28.09.2026 15:07:51
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's User_Controller compares the session user_type value with the required role by using PHP's loose inequality operator. U...
CVE-2026-85274
- EPSS 0.17%
- Veröffentlicht 25.09.2026 15:24:28
- Zuletzt bearbeitet 28.09.2026 15:07:51
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Recurring::stop() as a state-changing GET route without CSRF token validation. When an authenticated administrato...
CVE-2026-85290
- EPSS 0.24%
- Veröffentlicht 25.09.2026 15:23:20
- Zuletzt bearbeitet 29.09.2026 20:17:27
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from the URL path directly to the application log without neutralizing ...
CVE-2026-39372
- EPSS 0.28%
- Veröffentlicht 25.09.2026 15:21:53
- Zuletzt bearbeitet 29.09.2026 20:17:20
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores and serves uploaded image attachments without stripping EXIF metadata. When an administrator uploads an image thro...
- EPSS 0.23%
- Veröffentlicht 25.09.2026 15:19:21
- Zuletzt bearbeitet 28.09.2026 15:17:18
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores an administrator-controlled custom_field_table value without validating it against the allowed custom-field table ...
CVE-2026-26281
- EPSS 0.18%
- Veröffentlicht 18.02.2026 23:03:08
- Zuletzt bearbeitet 20.02.2026 17:14:02
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A stored cross-site scripting (XSS) vulnerability in the Sumex invoice view allows an authenticated user with client and invoice management privileges...
CVE-2026-26270
- EPSS 0.18%
- Veröffentlicht 18.02.2026 23:01:41
- Zuletzt bearbeitet 20.02.2026 17:13:26
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane (latest version) that allows an authenticated user with permissions to manage...
CVE-2026-25596
- EPSS 0.21%
- Veröffentlicht 18.02.2026 22:59:44
- Zuletzt bearbeitet 20.02.2026 17:07:57
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Product Unit Name fields. An authenticated administrator can in...
CVE-2026-25595
- EPSS 0.21%
- Veröffentlicht 18.02.2026 22:52:27
- Zuletzt bearbeitet 20.02.2026 17:07:50
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Invoice Number field. An authenticated administrator can inject...
CVE-2026-25594
- EPSS 0.21%
- Veröffentlicht 18.02.2026 22:50:45
- Zuletzt bearbeitet 20.02.2026 17:07:45
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Family Name field. The `family_name` value is rendered without ...