SolidInvoice vulnerabilities
CVEs whose affected-version data names the SolidInvoice package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-61614Medium· 5.9SolidInvoice is an open-source invoicing platform
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallback to the `X-API-TOKEN` header. This causes long-lived API credent…
▾ SunlitSolidInvoice · SolidInvoiceEPSS 0.28%via NVD
CVE-2026-61688Medium· 6.5PoCSolidInvoice is an open-source invoicing platform
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the same company by manipulating two writable Symfony UX LiveComponen…
▾ TwilightSolidInvoice · SolidInvoiceEPSS 0.26%via NVD