icz has 3 CVEs on record. The busiest recent month was April 2026 with 3. The median CVSS is 7.2 (high). Most affected products: matcha_invoice (2), matcha_sns (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.2
- Publish → KEV
- —
- Last 90 days
- 0 prev 3
Worst active — by depth score
CVE-2026-24913High· 8.8SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier48CVE-2026-33273High· 7.2Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier40CVE-2026-27787Medium· 5.4Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier30
icz vulnerabilities
CVEs affecting icz, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-33273High· 7.2Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier
Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be…
CVE-2026-27787Medium· 5.4Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier
Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.
CVE-2026-24913High· 8.8SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier
SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product.