CVE-2021-29023Medium· 5.3▾ SunlitInvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 29.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
0.8% → 1.2%
InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.
invoiceplane = 1.5.11Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-29024High· 7.5In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download
CVE-2021-29022Medium· 5.3In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.
CVE-2026-37603Medium· 6.5Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0
CVE-2026-85734Critical· 9.1LightRAG provides simple and fast retrieval-augmented generation
CVE-2026-56682Medium· 5.39Router is an AI router & token saver
CVE-2026-46649Critical· 9.1Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks