invoiceplane has 3 CVEs on record. The median CVSS is 5.3 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2021-29024High· 7.5In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download42CVE-2021-29023Medium· 5.3InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.29CVE-2021-29022Medium· 5.3In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.29
invoiceplane vulnerabilities
CVEs affecting invoiceplane, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2021-29024High· 7.5In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
▾ Twilightinvoiceplane · invoiceplaneEPSS 1.6%via NVD
CVE-2021-29023Medium· 5.3InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.
InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.
▾ Sunlitinvoiceplane · invoiceplaneEPSS 1.2%via NVD
CVE-2021-29022Medium· 5.3In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.
In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.
▾ Sunlitinvoiceplane · invoiceplaneEPSS 1.1%via NVD