Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-26270 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability… Invoiceplane Patch available Fix from $1,6002026-02-18 CRITICAL 9.1 CVE-2026-25548 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerabil… Invoiceplane 1.7.1+ Fix from $2,3002026-02-18 HIGH 7.5 CVE-2026-24745 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability… Invoiceplane Patch available Fix from $1,9502026-02-18 HIGH 7.5 CVE-2026-24743 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability… Invoiceplane Patch available Fix from $1,9502026-02-18 HIGH 7.5 CVE-2026-24744 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability… Invoiceplane Patch available Fix from $1,9502026-02-18 HIGH 7.5 CVE-2026-24746 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability… Invoiceplane Patch available Fix from $1,9502026-02-18 HIGH 7.5 CVE-2026-23491 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vulnerability exists in the `get… Invoiceplane 1.6.4+ Fix from $1,9502026-02-18 CRITICAL 9.9 CVE-2025-67084 File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can late… Invoiceplane 1.6.4+ Fix from $2,3002026-01-15 MEDIUM 6.5 CVE-2025-67082 An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generating a repo… Invoiceplane 1.6.4+ Fix from $1,6002026-01-15 MEDIUM 5.3 CVE-2025-67083 Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server. The ability to read f… Invoiceplane 1.6.4+ Fix from $1,6002026-01-15 CRITICAL 9.8 CVE-2024-56975 InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method o… Invoiceplane 1.6.2+ Fix from $2,3002025-03-28 MEDIUM 5.9 CVE-2024-12667 A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file… Invoiceplane after 1.6.1 Fix from $1,6002024-12-16 HIGH 8.8 CVE-2024-12478 A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the function upload_file of the f… Invoiceplane after 1.6.1 Fix from $1,9502024-12-16 MEDIUM 6.1 CVE-2023-23011 Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php. Invoiceplane No fix yet Fix from $1,6002023-02-07 HIGH 7.5 CVE-2021-29024 In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory trave… Invoiceplane Patch available Fix from $1,9502021-05-17 MEDIUM 5.3 CVE-2021-29023 InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable. Invoiceplane Patch available Fix from $1,6002021-05-17 MEDIUM 5.3 CVE-2021-29022 In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory. Invoiceplane No fix yet Fix from $1,6002021-05-10 MEDIUM 5.4 CVE-2019-7223 InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice"… Invoiceplane after 1.5.9 Fix from $1,6002019-03-21 MEDIUM 6.1 CVE-2018-12255 An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field. Invoiceplane No fix yet Fix from $1,6002018-07-03 MEDIUM 6.1 CVE-2017-18217 An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site … Invoiceplane 1.5.5+ Fix from $1,6002018-03-05 MEDIUM 6.1 CVE-2017-1000508 Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javas… Invoiceplane after 1.5.4 Fix from $1,6002018-02-09 HIGH 8.8 CVE-2017-1000238 InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver.… Invoiceplane No fix yet Fix from $1,9502017-11-17 MEDIUM 5.4 CVE-2017-1000239 InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious client sid… Invoiceplane No fix yet Fix from $1,6002017-11-17