Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

FOSSBilling — Vulnerabilities & Security Advisories 27

All 27 CVE vulnerabilities found in FOSSBilling, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses associated with FOSSBilling, an open-source billing and client management platform. It specifically addresses common vulnerability categories such as Cross-Site Scripting (XSS), SQL Injection, and improper access control flaws that may affect the integrity and confidentiality of the application. The content here aggregates data from various security advisories, vendor notifications, and public database entries to provide a comprehensive view of the product's security landscape. The collected information covers reported incidents and patches released over a multi-year period, offering historical context for each identified issue. By reviewing this aggregation, users can effectively track the vendor’s response to security disclosures over time, gaining insight into how quickly fixes are deployed and communicated. Additionally, this resource helps researchers and administrators understand the prevalence and impact of specific weakness classes within the FOSSBilling ecosystem. It serves as a reference for understanding the product’s vulnerability history, allowing stakeholders to assess risk exposure based on past incidents and remediation efforts. This centralized view supports informed decision-making for system updates and security hardening practices without relying on fragmented or disjointed sources of information.

Vendor: FOSSBilling

CVE IDTitleCVSSSeverityPublished
CVE-2026-53648 FOSSBilling: Downloadable product files can be overwritten through filename collisions CWE-73--2026-07-06
CVE-2026-53647 FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint CWE-200--2026-07-06
CVE-2026-53646 FOSSBilling: Client password reset token reuse allows persistent account takeover CWE-640--2026-07-06
CVE-2026-53645 FOSSBilling's missing self-edit prevention in staff permission management allows persistent privilege escalation CWE-269--2026-07-06
CVE-2026-53644 FOSSBilling's missing order-state validation allows clients to read and reset API key secrets for non-active orders CWE-639--2026-07-06
CVE-2026-53643 FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints CWE-200--2026-07-06
CVE-2026-53642 FOSSBilling: Unverified clients can access client-area pages when email confirmation is required CWE-863--2026-07-06
CVE-2026-53641 FOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literal CWE-79--2026-07-06
CVE-2026-53640 FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data CWE-200--2026-07-06
CVE-2026-43928 FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpayment CWE-754--2026-07-06
CVE-2026-43927 FOSSBilling has race condition in cart checkout that bypasses promo code usage limits CWE-367--2026-07-06
CVE-2026-43925 FOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code use CWE-915--2026-07-06
CVE-2026-43921 FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config serialization CWE-94--2026-07-06
CVE-2026-43918 Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flows CWE-613--2026-07-06
CVE-2026-42331 FOSSBilling missing authorization in guest Invoice API endpoints CWE-306--2026-07-06
CVE-2026-33734 FOSSBilling has improper SQL neutralization in `Massmailer` recipient filters CWE-89--2026-07-06
CVE-2026-42341 FOSSBilling has an unauthenticated payment bypass via IPN callback forgery CWE-306--2026-07-06
CVE-2026-43920 FOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance execution CWE-306--2026-06-25
CVE-2026-33543 FOSSBilling: Authentication bypass allows unauthenticated administrator creation CWE-288--2026-06-24
CVE-2026-27708 FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access CWE-284--2026-06-24
CVE-2026-23513 FOSSBilling: Broken Authorization in Client Transaction and Order Listings CWE-863--2026-06-23
CVE-2025-64105 FOSSBilling: IDOR Vulnerability in Support Ticket Creation CWE-639--2026-06-23
CVE-2026-27604 FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin Functions CWE-200--2026-06-23
CVE-2026-28496 FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE CWE-1336--2026-06-23
CVE-2026-43926 FOSSBilling's password reset confirmation endpoint lacks rate limiting CWE-204--2026-06-04
CVE-2026-43924 FOSSBilling has an open redirect via administrator-configured redirect targets CWE-601--2026-06-03
CVE-2026-40495 FOSSBilling version exposed via asset cache buster CWE-200--2026-06-03

All 27 known CVE vulnerabilities affecting FOSSBilling with full Chinese analysis, references, and POCs where available.