Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2026-26270
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability…
Invoiceplane
Patch available
CRITICAL 9.1
CVE-2026-25548
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerabil…
Invoiceplane
1.7.1+
HIGH 7.5
CVE-2026-24745
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability…
Invoiceplane
Patch available
HIGH 7.5
CVE-2026-24743
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability…
Invoiceplane
Patch available
HIGH 7.5
CVE-2026-24744
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability…
Invoiceplane
Patch available
HIGH 7.5
CVE-2026-24746
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability…
Invoiceplane
Patch available
HIGH 7.5
CVE-2026-23491
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vulnerability exists in the `get…
Invoiceplane
1.6.4+
CRITICAL 9.9
CVE-2025-67084
File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can late…
Invoiceplane
1.6.4+
MEDIUM 6.5
CVE-2025-67082
An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generating a repo…
Invoiceplane
1.6.4+
MEDIUM 5.3
CVE-2025-67083
Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server. The ability to read f…
Invoiceplane
1.6.4+
CRITICAL 9.8
CVE-2024-56975
InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method o…
Invoiceplane
1.6.2+
MEDIUM 5.9
CVE-2024-12667
A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file…
Invoiceplane
after 1.6.1
HIGH 8.8
CVE-2024-12478
A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the function upload_file of the f…
Invoiceplane
after 1.6.1
MEDIUM 6.1
CVE-2023-23011
Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.
Invoiceplane
No fix yet
HIGH 7.5
CVE-2021-29024
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory trave…
Invoiceplane
Patch available
MEDIUM 5.3
CVE-2021-29023
InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.
Invoiceplane
Patch available
MEDIUM 5.3
CVE-2021-29022
In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.
Invoiceplane
No fix yet
MEDIUM 5.4
CVE-2019-7223
InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice"…
Invoiceplane
after 1.5.9
MEDIUM 6.1
CVE-2018-12255
An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field.
Invoiceplane
No fix yet
MEDIUM 6.1
CVE-2017-18217
An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site …
Invoiceplane
1.5.5+
MEDIUM 6.1
CVE-2017-1000508
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javas…
Invoiceplane
after 1.5.4
HIGH 8.8
CVE-2017-1000238
InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver.…
Invoiceplane
No fix yet
MEDIUM 5.4
CVE-2017-1000239
InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious client sid…
Invoiceplane
No fix yet