SolidInvoice has 3 CVEs on record. 2 were published in the last 90 days. The median CVSS is 6.2 (medium). Most affected products: SolidInvoice (2), solidinvoice/solidinvoice (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.2
- Publish → KEV
- —
- Last 90 days
- 2 prev 1
Worst active — by depth score
CVE-2026-61688Medium· 6.5SolidInvoice is an open-source invoicing platform48GHSA-7vfx-4246-jcfhHighSolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings41CVE-2026-61614Medium· 5.9SolidInvoice is an open-source invoicing platform33
SolidInvoice vulnerabilities
CVEs affecting SolidInvoice, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-61614Medium· 5.9SolidInvoice is an open-source invoicing platform
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallback to the `X-API-TOKEN` header. This causes long-lived API credent…
CVE-2026-61688Medium· 6.5PoCSolidInvoice is an open-source invoicing platform
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the same company by manipulating two writable Symfony UX LiveComponen…
GHSA-7vfx-4246-jcfhHighSolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings
SolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings