Vulnerabilities
29 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-23491 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vulnerability exists in the `get_file` method of the `Guest` module's `Get` controller in InvoicePlane up to and including through 1.6.3. The vulnerability allows unauthenticated attackers to read arbitrary files on the server by manipulating the input filename. This leads to the disclosure of sensitive information, including configuration files with database credentials. Version 1.6.4 fixes the issue. NVD description · AI analysis pending | 9.3 group max | 4% | PoC |
| — | |
| CVE-2025-67084 | File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be execut File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE). NVD description · AI analysis pending | 9.9 group max | <1% | PoC |
| — | |
| CVE-2025-64012 | InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. The invoices/view handler fails to verify ownership before returning invoice data. NVD description · AI analysis pending | 4.3 | <1% | PoC |
| — | |
| CVE-2024-56975 | InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Uploa InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-12667 | A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.2-beta-1 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. NVD description · AI analysis pending | 6.3 group max | <1% |
| — | ||
| CVE-2023-23011 | Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php. Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php. NVD description · AI analysis pending | 6.1 | <1% | PoC ×2 |
| — | |
| CVE-2021-29024 +1 in the same advisory: …29023 | In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication. NVD description · AI analysis pending | 7.5 group max | 2% | PoC |
| — | |
| CVE-2021-29022 | In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory. In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory. NVD description · AI analysis pending | 5.3 | 1% | PoC |
| — | |
| CVE-2019-7223 | InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice" option. InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice" option. The XSS payload is rendered at an index.php/invoices/view/## URI. NOTE: this is different from CVE-2018-12255. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2018-12255 | An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field. An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2017-18217 | An issue was discovered in InvoicePlane before 1.5.5. An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and application/modules/quotes/views/view.php. NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — | |
| CVE-2017-1000508 | Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later. NVD description · AI analysis pending | 6.1 | 1% |
| — | ||
| CVE-2017-1000238 +1 in the same advisory: …1000239 | InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacker to upload a script which is able to compromise the webserver. NVD description · AI analysis pending | 8.8 group max | 1% | PoC |
| — |