CVE-2026-25548
- EPSS 0.77%
- Veröffentlicht 18.02.2026 22:49:15
- Zuletzt bearbeitet 20.02.2026 18:45:32
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7.0 through a chained Local File Inclusion (LFI) and Log Poisoning attac...
CVE-2026-24745
- EPSS 0.22%
- Veröffentlicht 18.02.2026 22:47:19
- Zuletzt bearbeitet 20.02.2026 18:45:21
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the upload Login Logo functions of InvoicePlane version 1.7.0. In the Upload Login Logo, t...
CVE-2026-24744
- EPSS 0.22%
- Veröffentlicht 18.02.2026 21:01:27
- Zuletzt bearbeitet 20.02.2026 18:45:14
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the Edit Invoices functions of InvoicePlane version 1.7.0. When editing invoices, the appl...
CVE-2026-24743
- EPSS 0.22%
- Veröffentlicht 18.02.2026 20:59:16
- Zuletzt bearbeitet 20.02.2026 18:39:46
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the upload Invoice Logo functions of InvoicePlane version 1.7.0. The Upload Invoice Logo f...
CVE-2026-24746
- EPSS 0.28%
- Veröffentlicht 18.02.2026 20:51:20
- Zuletzt bearbeitet 20.02.2026 18:33:43
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the Edit Quotes functions of InvoicePlane version 1.7.0. In the Editing Quotes function, t...
CVE-2026-23491
- EPSS 1.05%
- Veröffentlicht 18.02.2026 19:52:26
- Zuletzt bearbeitet 25.02.2026 17:25:38
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vulnerability exists in the `get_file` method of the `Guest` module's `Get` controller in InvoicePlane up to and including through 1....
CVE-2025-67084
- EPSS 0.42%
- Veröffentlicht 15.01.2026 15:15:51
- Zuletzt bearbeitet 22.01.2026 16:03:34
File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).
CVE-2025-67083
- EPSS 0.63%
- Veröffentlicht 15.01.2026 15:15:51
- Zuletzt bearbeitet 22.01.2026 16:03:54
Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server. The ability to read files and the file type depends on the web server and its configuration.
CVE-2025-67082
- EPSS 0.28%
- Veröffentlicht 15.01.2026 15:15:51
- Zuletzt bearbeitet 22.01.2026 16:04:15
An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generating a report. An authenticated attacker can exploit this issue via error-based SQL injection, allowing for the ...
CVE-2025-64012
- EPSS 0.29%
- Veröffentlicht 16.12.2025 00:00:00
- Zuletzt bearbeitet 31.12.2025 00:39:06
InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. The invoices/view handler fails to verify ownership before returning invoice data.