Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-85293— InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mailer Forms

Quick assessment

Affected
InvoicePlane InvoicePlane
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

InvoicePlane 是一款用于管理发票、客户和付款的自托管开源应用程序。在版本 1.7.2-beta-1 中,InvoicePlane 在存储客户邮箱地址(client_email)时未强制执行邮箱语法校验,并在发票邮件表单(invoice mailer form)和报价邮件表单(quote mailer form)中,将这些邮箱值以未转义的方式渲染在双引号包裹的属性值内部。具备编辑客户权限的管理员可注入破坏 HTML 属性结构的恶意输入;当邮件发送器功能已配置时,其他已认证管理员在打开相关邮件页面时将触发

CVSS 4.8 · Medium EPSS 0.22% · P12
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85293

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mailer Forms
Source: CVE Program / CVE List V5
Vulnerability Description
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-beta-1, InvoicePlane stores client_email values without enforcing email syntax and renders them unescaped inside double-quoted value attributes in the invoice mailer form and quote mailer form. An administrator who can edit a client can store attribute-breaking input, and, when the mailer is configured, JavaScript executes when another authenticated administrator opens the related mailer page. The script runs in the InvoicePlane origin and can perform same-origin actions with the victim's session. This issue is fixed in version 1.7.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
InvoicePlane InvoicePlane < 1.7.2 -

II. Public POCs for CVE-2026-85293

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85293

请登录查看更多情报信息。

Other References for CVE-2026-85293 (4)

Same Patch Batch · InvoicePlane · 2026-09-25 · 13 CVEs total

CVE-2026-39353 9.1 CRITICAL InvoicePlane: Remote Code Execution via Writable Templates Directory
CVE-2026-88003 7.5 HIGH InvoicePlane: Failure to Revoke Administrative Privileges After Role Downgrade
CVE-2026-49850 7.5 HIGH InvoicePlane: Missing CSRF Protection on State-Changing delete Actions
CVE-2026-50547 7.5 HIGH InvoicePlane permits local file inclusion through the e-invoice XML configuration identifi
CVE-2026-33639 7.2 HIGH InvoicePlane permits DDL injection through tax_rate_decimal_places
CVE-2026-85291 6.5 MEDIUM InvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Without Authorizati
CVE-2026-85274 6.5 MEDIUM InvoicePlane: Recurring Invoice State Change via GET Request Without CSRF Protection
CVE-2026-85289 6.5 MEDIUM InvoicePlane: Missing CSRF Token Validation on Multiple Delete Endpoints
CVE-2026-54790 6.0 MEDIUM InvoicePlane: Second-order SQL injection through the unvalidated custom_field_table field
CVE-2026-85290 5.3 MEDIUM InvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error Logging
CVE-2026-39372 4.9 MEDIUM InvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in Attachments
CVE-2026-85292 4.8 MEDIUM InvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-Depth)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85293

No comments yet


Leave a comment