Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Invoiceplane MEDIUM 5.4
CVE-2026-26270

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability…

Patch available
Fix from $1,600 2026-02-18
Invoiceplane CRITICAL 9.1
CVE-2026-25548

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerabil…

Fix: 1.7.1+
Fix from $2,300 2026-02-18
Invoiceplane HIGH 7.5
CVE-2026-24745

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability…

Patch available
Fix from $1,950 2026-02-18
Invoiceplane HIGH 7.5
CVE-2026-24743

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability…

Patch available
Fix from $1,950 2026-02-18
Invoiceplane HIGH 7.5
CVE-2026-24744

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability…

Patch available
Fix from $1,950 2026-02-18
Invoiceplane HIGH 7.5
CVE-2026-24746

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability…

Patch available
Fix from $1,950 2026-02-18
Invoiceplane HIGH 7.5
CVE-2026-23491

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vulnerability exists in the `get…

Fix: 1.6.4+
Fix from $1,950 2026-02-18
Invoiceplane CRITICAL 9.9
CVE-2025-67084

File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can late…

Fix: 1.6.4+
Fix from $2,300 2026-01-15
Invoiceplane MEDIUM 6.5
CVE-2025-67082

An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generating a repo…

Fix: 1.6.4+
Fix from $1,600 2026-01-15
Invoiceplane MEDIUM 5.3
CVE-2025-67083

Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server. The ability to read f…

Fix: 1.6.4+
Fix from $1,600 2026-01-15
Invoiceplane CRITICAL 9.8
CVE-2024-56975

InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method o…

Fix: 1.6.2+
Fix from $2,300 2025-03-28
Invoiceplane MEDIUM 5.9
CVE-2024-12667

A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file…

Fix: after 1.6.1
Fix from $1,600 2024-12-16
Invoiceplane HIGH 8.8
CVE-2024-12478

A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the function upload_file of the f…

Fix: after 1.6.1
Fix from $1,950 2024-12-16
Invoiceplane MEDIUM 6.1
CVE-2023-23011

Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.

No fix yet
Fix from $1,600 2023-02-07
Invoiceplane HIGH 7.5
CVE-2021-29024

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory trave…

Patch available
Fix from $1,950 2021-05-17
Invoiceplane MEDIUM 5.3
CVE-2021-29023

InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.

Patch available
Fix from $1,600 2021-05-17
Invoiceplane MEDIUM 5.3
CVE-2021-29022

In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.

No fix yet
Fix from $1,600 2021-05-10
Invoiceplane MEDIUM 5.4
CVE-2019-7223

InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice"…

Fix: after 1.5.9
Fix from $1,600 2019-03-21
Invoiceplane MEDIUM 6.1
CVE-2018-12255

An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field.

No fix yet
Fix from $1,600 2018-07-03
Invoiceplane MEDIUM 6.1
CVE-2017-18217

An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site …

Fix: 1.5.5+
Fix from $1,600 2018-03-05
Invoiceplane MEDIUM 6.1
CVE-2017-1000508

Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javas…

Fix: after 1.5.4
Fix from $1,600 2018-02-09
Invoiceplane HIGH 8.8
CVE-2017-1000238

InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver.…

No fix yet
Fix from $1,950 2017-11-17
Invoiceplane MEDIUM 5.4
CVE-2017-1000239

InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious client sid…

No fix yet
Fix from $1,600 2017-11-17