CVE-2026-71626
- EPSS 0.17%
- Veröffentlicht 04.09.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 16:04:24
An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components
CVE-2026-83744
- EPSS 0.2%
- Veröffentlicht 01.09.2026 05:17:10
- Zuletzt bearbeitet 02.09.2026 18:21:28
A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability affects the function Purify::isHostSafe of the file app/Services/Pdf/Purify.php of the component invoices Endpoint. The manipulation of the arg...
CVE-2026-83743
- EPSS 0.22%
- Veröffentlicht 01.09.2026 04:30:16
- Zuletzt bearbeitet 01.09.2026 20:47:54
A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipulation of the argument vendor_contact can lead to au...
CVE-2026-71233
- EPSS 0.2%
- Veröffentlicht 05.08.2026 10:56:18
- Zuletzt bearbeitet 26.08.2026 17:13:24
InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.
CVE-2026-58450
- EPSS 0.18%
- Veröffentlicht 30.06.2026 21:07:25
- Zuletzt bearbeitet 14.07.2026 23:17:30
Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthenticated attackers to redirect authenticated victims to attacker-controlled external URLs by injecting a malicious value into the inte...
CVE-2026-29925
- EPSS 0.32%
- Veröffentlicht 30.03.2026 00:00:00
- Zuletzt bearbeitet 02.04.2026 16:58:36
Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.
CVE-2026-33742
- EPSS 0.2%
- Veröffentlicht 26.03.2026 20:50:21
- Zuletzt bearbeitet 30.03.2026 17:02:40
Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Product notes fields in Invoice Ninja v5.13.0 allow raw HTML via Markdown rendering, enabling stored XSS. The Markdown parser output was not sanitiz...
CVE-2026-33628
- EPSS 0.23%
- Veröffentlicht 26.03.2026 20:48:45
- Zuletzt bearbeitet 30.03.2026 17:24:09
Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item descriptions in Invoice Ninja v5.13.0 bypass the XSS denylist filter, allowing stored XSS payloads to execute when invoices are re...
CVE-2026-0649
- EPSS 0.23%
- Veröffentlicht 07.01.2026 00:32:07
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security vulnerability has been detected in invoiceninja up to 5.12.38. The affected element is the function copy of the file /app/Jobs/Util/Import.php of the component Migration Import. The manipulation of the argument company_logo leads to server...
CVE-2025-8700
- EPSS 0.14%
- Veröffentlicht 26.08.2025 12:23:04
- Zuletzt bearbeitet 15.04.2026 00:35:42
Invoice Ninja's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", allows local attackers with unprivileged access (e.g. via a malicious application) to attach a debugger, read or modify the process ...