VulnSea

InvoicePlane vulnerabilities

CVEs whose affected-version data names the InvoicePlane package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

15 CVEsRSS

CVE-2026-85290Medium· 5.3
today

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from the URL path directly to the application log without …

▾ SunlitInvoicePlane · InvoicePlanevia NVD
CVE-2026-54790Medium· 6.0
today

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores an administrator-controlled custom_field_table value without validating it against the allowed custom…

▾ SunlitInvoicePlane · InvoicePlanevia NVD
CVE-2026-39372Medium· 4.9
today

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores and serves uploaded image attachments without stripping EXIF metadata. When an administrator uploads …

▾ SunlitInvoicePlane · InvoicePlanevia NVD
CVE-2026-85292Medium· 4.8
today

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's User_Controller compares the session user_type value with the required role by using PHP's loose inequalit…

▾ SunlitInvoicePlane · InvoicePlanevia NVD
CVE-2026-85291Medium· 6.5
today

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Users::change_password() method accepts a user_id from the URL and updates that account's password without…

▾ SunlitInvoicePlane · InvoicePlanevia NVD
CVE-2026-85274Medium· 6.5PoC
today

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Recurring::stop() as a state-changing GET route without CSRF token validation. When an authenticated…

▾ TwilightInvoicePlane · InvoicePlanevia NVD
CVE-2026-39353Critical· 9.1PoC
today

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an …

▾ AbyssalInvoicePlane · InvoicePlanevia NVD
CVE-2026-50547High· 7.5
today

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Invoices::generate_xml() method appends a database-derived xml_id to the XMLconfigs helper directory and i…

▾ TwilightInvoicePlane · InvoicePlanevia NVD
CVE-2026-33639High· 7.2
today

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for …

▾ TwilightInvoicePlane · InvoicePlanevia NVD
CVE-2026-49850High· 7.5
today

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without requiring POS…

▾ TwilightInvoicePlane · InvoicePlanevia NVD
CVE-2026-85289Medium· 6.5PoC
today

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane omits ensure_valid_post_request() from delete methods including Payments::delete(), Recurring::delete(), and…

▾ TwilightInvoicePlane · InvoicePlanevia NVD
CVE-2026-85293Medium· 4.8PoC
today

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-beta-1, InvoicePlane stores client_email values without enforcing email syntax and renders them unescaped inside double-…

▾ TwilightInvoicePlane · InvoicePlanevia NVD
CVE-2021-29024High· 7.5
5y ago

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.

▾ Twilightinvoiceplane · invoiceplaneEPSS 1.6%via NVD
CVE-2021-29023Medium· 5.3
5y ago

InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.

InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.

▾ Sunlitinvoiceplane · invoiceplaneEPSS 1.2%via NVD
CVE-2021-29022Medium· 5.3
5y ago

In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.

In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.

▾ Sunlitinvoiceplane · invoiceplaneEPSS 1.1%via NVD
InvoicePlane vulnerabilities (CVEs) · VulnSea