InvoicePlane has 15 CVEs on record between 2021 and 2026. Disclosure cadence is accelerating: 12 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 12. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-98 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 12 prev 0
Worst active — by depth score
CVE-2026-39353Critical· 9.1InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments62CVE-2026-85289Medium· 6.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments48CVE-2026-85274Medium· 6.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments48CVE-2021-29024High· 7.5In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download42CVE-2026-50547High· 7.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments41
InvoicePlane vulnerabilities
CVEs affecting InvoicePlane, newest first. Open any entry for full detail, references, and exploit status.
15 CVEsRSS
CVE-2026-85290Medium· 5.3InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from the URL path directly to the application log without …
CVE-2026-54790Medium· 6.0InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores an administrator-controlled custom_field_table value without validating it against the allowed custom…
CVE-2026-39372Medium· 4.9InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores and serves uploaded image attachments without stripping EXIF metadata. When an administrator uploads …
CVE-2026-85292Medium· 4.8InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's User_Controller compares the session user_type value with the required role by using PHP's loose inequalit…
CVE-2026-85291Medium· 6.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Users::change_password() method accepts a user_id from the URL and updates that account's password without…
CVE-2026-85274Medium· 6.5PoCInvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Recurring::stop() as a state-changing GET route without CSRF token validation. When an authenticated…
CVE-2026-39353Critical· 9.1PoCInvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an …
CVE-2026-50547High· 7.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Invoices::generate_xml() method appends a database-derived xml_id to the XMLconfigs helper directory and i…
CVE-2026-33639High· 7.2InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for …
CVE-2026-49850High· 7.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without requiring POS…
CVE-2026-85289Medium· 6.5PoCInvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane omits ensure_valid_post_request() from delete methods including Payments::delete(), Recurring::delete(), and…
CVE-2026-85293Medium· 4.8PoCInvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-beta-1, InvoicePlane stores client_email values without enforcing email syntax and renders them unescaped inside double-…
CVE-2021-29024High· 7.5In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
CVE-2021-29023Medium· 5.3InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.
InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.
CVE-2021-29022Medium· 5.3In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.
In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.