Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-54790— InvoicePlane: Second-order SQL injection through the unvalidated custom_field_table field in the Custom Fields module

Quick assessment

Affected
InvoicePlane InvoicePlane
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

InvoicePlane 是一款自托管的开源应用程序,用于管理发票、客户和支付。在版本 1.7.2 之前,InvoicePlane 会存储由管理员控制的 值,但并未对该值进行验证,未将其与允许的自定义字段表名称进行比对。随后,在 函数中,该存储的值被拼接进 SQL 查询的 表名和 列标识符位置。因此,当打开自定义字段编辑表单时,会触发一次二级 SQL 注入。攻击者可以利用此漏洞查询任意 schema 的数据,并可能导致应用程序出错或服务中断(拒绝服务)。该问题已在版本 1.7.2 中得到修复。

CVSS 6.0 · Medium EPSS 0.23% · P13
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54790

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
InvoicePlane: Second-order SQL injection through the unvalidated custom_field_table field in the Custom Fields module
Source: CVE Program / CVE List V5
Vulnerability Description
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores an administrator-controlled custom_field_table value without validating it against the allowed custom-field table names. Mdl_custom_fields::used() later concatenates that stored value into the FROM table and WHERE column identifier positions, so opening the custom-field edit form executes a second-order SQL injection. The injection can query arbitrary schema data and can cause application errors or denial of service. This issue is fixed in version 1.7.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
InvoicePlane InvoicePlane < 1.7.2 -

II. Public POCs for CVE-2026-54790

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54790

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-54790 (2)

Vendor Advisories for CVE-2026-54790 (1)

Vendor Pages for CVE-2026-54790 (1)

Same Patch Batch · InvoicePlane · 2026-09-25 · 13 CVEs total

CVE-2026-39353 9.1 CRITICAL InvoicePlane: Remote Code Execution via Writable Templates Directory
CVE-2026-88003 7.5 HIGH InvoicePlane: Failure to Revoke Administrative Privileges After Role Downgrade
CVE-2026-49850 7.5 HIGH InvoicePlane: Missing CSRF Protection on State-Changing delete Actions
CVE-2026-50547 7.5 HIGH InvoicePlane permits local file inclusion through the e-invoice XML configuration identifi
CVE-2026-33639 7.2 HIGH InvoicePlane permits DDL injection through tax_rate_decimal_places
CVE-2026-85291 6.5 MEDIUM InvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Without Authorizati
CVE-2026-85274 6.5 MEDIUM InvoicePlane: Recurring Invoice State Change via GET Request Without CSRF Protection
CVE-2026-85289 6.5 MEDIUM InvoicePlane: Missing CSRF Token Validation on Multiple Delete Endpoints
CVE-2026-85290 5.3 MEDIUM InvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error Logging
CVE-2026-39372 4.9 MEDIUM InvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in Attachments
CVE-2026-85292 4.8 MEDIUM InvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-Depth)
CVE-2026-85293 4.8 MEDIUM InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mail

IV. Related Vulnerabilities

V. Comments for CVE-2026-54790

No comments yet


Leave a comment