InvoicePlane 是一款自托管的开源应用程序,用于管理发票、客户和支付。在版本 1.7.2 之前,InvoicePlane 会存储由管理员控制的 值,但并未对该值进行验证,未将其与允许的自定义字段表名称进行比对。随后,在 函数中,该存储的值被拼接进 SQL 查询的 表名和 列标识符位置。因此,当打开自定义字段编辑表单时,会触发一次二级 SQL 注入。攻击者可以利用此漏洞查询任意 schema 的数据,并可能导致应用程序出错或服务中断(拒绝服务)。该问题已在版本 1.7.2 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| InvoicePlane | InvoicePlane | < 1.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-39353 | 9.1 CRITICAL | InvoicePlane: Remote Code Execution via Writable Templates Directory |
| CVE-2026-88003 | 7.5 HIGH | InvoicePlane: Failure to Revoke Administrative Privileges After Role Downgrade |
| CVE-2026-49850 | 7.5 HIGH | InvoicePlane: Missing CSRF Protection on State-Changing delete Actions |
| CVE-2026-50547 | 7.5 HIGH | InvoicePlane permits local file inclusion through the e-invoice XML configuration identifi |
| CVE-2026-33639 | 7.2 HIGH | InvoicePlane permits DDL injection through tax_rate_decimal_places |
| CVE-2026-85291 | 6.5 MEDIUM | InvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Without Authorizati |
| CVE-2026-85274 | 6.5 MEDIUM | InvoicePlane: Recurring Invoice State Change via GET Request Without CSRF Protection |
| CVE-2026-85289 | 6.5 MEDIUM | InvoicePlane: Missing CSRF Token Validation on Multiple Delete Endpoints |
| CVE-2026-85290 | 5.3 MEDIUM | InvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error Logging |
| CVE-2026-39372 | 4.9 MEDIUM | InvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in Attachments |
| CVE-2026-85292 | 4.8 MEDIUM | InvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-Depth) |
| CVE-2026-85293 | 4.8 MEDIUM | InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mail |
No comments yet