invoiceplane vulnerabilities
CVEs whose affected-version data names the invoiceplane package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2021-29024High· 7.5In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
▾ Twilightinvoiceplane · invoiceplaneEPSS 1.6%via NVD
CVE-2021-29023Medium· 5.3InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.
InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.
▾ Sunlitinvoiceplane · invoiceplaneEPSS 1.2%via NVD
CVE-2021-29022Medium· 5.3In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.
In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.
▾ Sunlitinvoiceplane · invoiceplaneEPSS 1.1%via NVD