matcha_invoice vulnerabilities
CVEs whose affected-version data names the matcha_invoice package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-33273High· 7.2Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier
Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be…
▾ Twilighticz · matcha_invoiceEPSS 0.23%via NVD
CVE-2026-24913High· 8.8SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier
SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product.
▾ Twilighticz · matcha_invoiceEPSS 0.30%via NVD