{"id":"CVE-2026-24913","title":"SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier","summary":"SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product.","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-89"],"vendor":"icz","product":"matcha_invoice","affected":["matcha_invoice <= 2.6.6"],"published":"2026-04-08","updated":"2026-07-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-24913","references":[{"url":"https://jvn.jp/en/jp/JVN33581068/","label":"vultures@jpcert.or.jp"},{"url":"https://oss.icz.co.jp/news/?p=1386","label":"vultures@jpcert.or.jp"}],"tags":["nvd"],"epss":0.00301,"epssPercentile":0.22984,"ingestedAt":"2026-07-25T23:05:58.751Z","slug":"CVE-2026-24913","body":"## Overview\n\nSQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product.\n\n## Affected\n\n- `matcha_invoice <= 2.6.6`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}