InvoicePlane是InvoicePlane开源的一个应用软件。提供一个自托管的开源应用程序,用于管理您的报价,发票,客户和付款。 InvoicePlane 1.7.0版本存在安全漏洞,该漏洞源于通过链接本地文件包含和日志投毒攻击,可能导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| InvoicePlane | InvoicePlane | <= 1.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-24746 | 5.7 MEDIUM | InvoicePlane has a Stored Cross-Site Scripting (XSS) issue |
| CVE-2026-24744 | 5.7 MEDIUM | InvoicePlane has a Stored Cross-Site Scripting (XSS) issue |
| CVE-2026-24745 | 5.7 MEDIUM | InvoicePlane has a Stored Cross-Site Scripting (XSS) issue |
| CVE-2026-24743 | 5.7 MEDIUM | InvoicePlane has a Stored Cross-Site Scripting (XSS) issue |
| CVE-2026-26270 | 5.4 MEDIUM | InvoicePlane has Stored Cross-Site Scripting Issue in Identifier Formatting |
| CVE-2026-25594 | 4.8 MEDIUM | InvoicePlane has Stored XSS via Family Name in Product Form |
| CVE-2026-25596 | 4.8 MEDIUM | InvoicePlane has Stored XSS via Product Unit Name in Invoice Item List |
| CVE-2026-25595 | 4.8 MEDIUM | InvoicePlane has Stored XSS via Invoice Number in Invoice View and Dashboard |
| CVE-2026-26281 | 4.4 MEDIUM | InvoicePlane has Stored Cross-Site Scripting (XSS) Issue in Sumex Invoice View |
| CVE-2026-23491 | InvoicePlane has Unauthenticated Path Traversal in Guest Controller |
No comments yet