InvoicePlane 是一个自托管的开源应用,用于管理发票、客户和付款。在 1.7.2 版本之前,InvoicePlane 将 方法暴露为一个可改变系统状态的 GET 路由,且未进行 CSRF 令牌验证。当经过身份验证的管理员加载由攻击者控制的、包含对 路径请求的内容时,应用程序会停止选定的循环发票。攻击者可以利用多个标识符来中断循环计费,从而导致经济损失。该问题已在 1.7.2 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| InvoicePlane | InvoicePlane | < 1.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-39353 | 9.1 CRITICAL | InvoicePlane: Remote Code Execution via Writable Templates Directory |
| CVE-2026-88003 | 7.5 HIGH | InvoicePlane: Failure to Revoke Administrative Privileges After Role Downgrade |
| CVE-2026-49850 | 7.5 HIGH | InvoicePlane: Missing CSRF Protection on State-Changing delete Actions |
| CVE-2026-50547 | 7.5 HIGH | InvoicePlane permits local file inclusion through the e-invoice XML configuration identifi |
| CVE-2026-33639 | 7.2 HIGH | InvoicePlane permits DDL injection through tax_rate_decimal_places |
| CVE-2026-85291 | 6.5 MEDIUM | InvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Without Authorizati |
| CVE-2026-85289 | 6.5 MEDIUM | InvoicePlane: Missing CSRF Token Validation on Multiple Delete Endpoints |
| CVE-2026-54790 | 6.0 MEDIUM | InvoicePlane: Second-order SQL injection through the unvalidated custom_field_table field |
| CVE-2026-85290 | 5.3 MEDIUM | InvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error Logging |
| CVE-2026-39372 | 4.9 MEDIUM | InvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in Attachments |
| CVE-2026-85292 | 4.8 MEDIUM | InvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-Depth) |
| CVE-2026-85293 | 4.8 MEDIUM | InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mail |
No comments yet