---
id: CVE-2026-61688
title: SolidInvoice is an open-source invoicing platform
summary: >-
  SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an
  authenticated user can view the API request history of any other user's API
  tokens within the same company by manipulating two writable Symfony UX
  LiveComponen…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-639
vendor: SolidInvoice
product: SolidInvoice
affected:
  - SolidInvoice < 3.0.1
published: '2026-09-04'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:13:07.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61688'
references:
  - url: 'https://github.com/SolidInvoice/SolidInvoice/releases/tag/3.0.1'
    label: security-advisories@github.com
  - url: >-
      https://github.com/SolidInvoice/SolidInvoice/security/advisories/GHSA-jhv9-9fv9-67cr
    label: security-advisories@github.com
  - url: >-
      https://github.com/SolidInvoice/SolidInvoice/security/advisories/GHSA-jhv9-9fv9-67cr
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00354
epssPercentile: 0.263
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T17:43:36.910517Z'
ingestedAt: '2026-09-08T18:07:34.885Z'
---

## Overview

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the same company by manipulating two writable Symfony UX LiveComponent props on the `DataGrid` component. Version 3.0.1 fixes the issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
