InvoicePlane 是一款用于管理发票、客户和付款的自托管开源应用程序。在版本 1.7.2 之前,InvoicePlane 将 和 暴露为无需 POST 请求即可触发的状态变更路由,且未验证 CSRF 令牌。当经过身份验证的管理员加载攻击者控制的、请求上述受影响路由的内容时,该应用程序可能会删除发票或发票税务记录。这种跨站请求伪造(CSRF)攻击可在未经管理员意愿的情况下移除财务数据。该问题已在版本 1.7.2 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| InvoicePlane | InvoicePlane | < 1.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-39353 | 9.1 CRITICAL | InvoicePlane: Remote Code Execution via Writable Templates Directory |
| CVE-2026-88003 | 7.5 HIGH | InvoicePlane: Failure to Revoke Administrative Privileges After Role Downgrade |
| CVE-2026-50547 | 7.5 HIGH | InvoicePlane permits local file inclusion through the e-invoice XML configuration identifi |
| CVE-2026-33639 | 7.2 HIGH | InvoicePlane permits DDL injection through tax_rate_decimal_places |
| CVE-2026-85291 | 6.5 MEDIUM | InvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Without Authorizati |
| CVE-2026-85274 | 6.5 MEDIUM | InvoicePlane: Recurring Invoice State Change via GET Request Without CSRF Protection |
| CVE-2026-85289 | 6.5 MEDIUM | InvoicePlane: Missing CSRF Token Validation on Multiple Delete Endpoints |
| CVE-2026-54790 | 6.0 MEDIUM | InvoicePlane: Second-order SQL injection through the unvalidated custom_field_table field |
| CVE-2026-85290 | 5.3 MEDIUM | InvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error Logging |
| CVE-2026-39372 | 4.9 MEDIUM | InvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in Attachments |
| CVE-2026-85292 | 4.8 MEDIUM | InvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-Depth) |
| CVE-2026-85293 | 4.8 MEDIUM | InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mail |
No comments yet