InvoicePlane 是一款自托管的开源应用,用于管理发票、客户和支付。在 1.7.2 版本之前,InvoicePlane 在其删除方法(包括 Payments::delete()、Recurring::delete() 和 User_clients::delete())中未调用 ensure_valid_post_request()。尽管这些路由要求使用 POST 请求,但应用并未验证请求的 CSRF 令牌。攻击者可以利用已认证管理员的浏览器提交跨站请求(CSRF),从而删除财务记录及其他应用程序数据。该问题
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| InvoicePlane | InvoicePlane | < 1.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-39353 | 9.1 CRITICAL | InvoicePlane: Remote Code Execution via Writable Templates Directory |
| CVE-2026-88003 | 7.5 HIGH | InvoicePlane: Failure to Revoke Administrative Privileges After Role Downgrade |
| CVE-2026-49850 | 7.5 HIGH | InvoicePlane: Missing CSRF Protection on State-Changing delete Actions |
| CVE-2026-50547 | 7.5 HIGH | InvoicePlane permits local file inclusion through the e-invoice XML configuration identifi |
| CVE-2026-33639 | 7.2 HIGH | InvoicePlane permits DDL injection through tax_rate_decimal_places |
| CVE-2026-85291 | 6.5 MEDIUM | InvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Without Authorizati |
| CVE-2026-85274 | 6.5 MEDIUM | InvoicePlane: Recurring Invoice State Change via GET Request Without CSRF Protection |
| CVE-2026-54790 | 6.0 MEDIUM | InvoicePlane: Second-order SQL injection through the unvalidated custom_field_table field |
| CVE-2026-85290 | 5.3 MEDIUM | InvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error Logging |
| CVE-2026-39372 | 4.9 MEDIUM | InvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in Attachments |
| CVE-2026-85292 | 4.8 MEDIUM | InvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-Depth) |
| CVE-2026-85293 | 4.8 MEDIUM | InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mail |
No comments yet