| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-33742 | Invoice Ninja has Stored XSS via Markdown HTML Injection in Product Notes | invoiceninja | invoiceninja | Medium | 5.4 | 2026-03-26 20:50:22 | Deep Dive |
| CVE-2026-33628 | Invoice Ninja Denylist Bypass may Lead to Stored XSS via Invoice Line Items | invoiceninja | invoiceninja | Medium | 5.4 | 2026-03-26 20:48:46 | Deep Dive |
| CVE-2026-0649 | invoiceninja Migration Import Import.php copy server-side request forgery | - | invoiceninja | Medium | 4.7 | 2026-01-07 00:32:08 | Deep Dive |
| CVE-2021-3977 | Cross-site Scripting (XSS) - Stored in invoiceninja/invoiceninja | invoiceninja | invoiceninja/invoiceninja | 中危 | - | 2021-12-24 20:10:10 | Deep Dive |