Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

FOSSBilling — Vulnerabilities & Security Advisories 27

All 27 CVE vulnerabilities found in FOSSBilling, with AI-generated Chinese analysis, references, and POCs.

This page catalogs security vulnerabilities associated with FOSSBilling, an open-source billing and client management system developed by FOSSBilling. It aggregates known weaknesses within the software, focusing on the Common Weakness Enumeration (CWE) taxonomy to provide structured insights into the product's security posture. The content compiled here covers a broad spectrum of vulnerability types, including cross-site scripting, SQL injection, and improper access control issues, spanning from the earliest public disclosures to recent patch releases. This comprehensive time range ensures that historical context is preserved alongside current threat intelligence. By consulting this aggregation, users can effectively track vendor advisories issued by the FOSSBilling development team and community contributors. It also allows researchers and security professionals to understand specific weakness classes as they manifest within this particular ecosystem, facilitating deeper analysis of code flaws. Furthermore, visitors can look up the product's vulnerability history to assess long-term stability and the efficacy of past remediation efforts. This resource serves as a centralized reference point for evaluating the risk profile of FOSSBilling deployments. It is designed to support informed decision-making for administrators, developers, and security auditors who rely on this tool for their business operations. The goal is to provide clarity and accessibility regarding the security landscape of this specific open-source project without unnecessary complexity or noise.

Vendor: FOSSBilling

CVE ID Title CVSS Severity Published
CVE-2026-53648 FOSSBilling: Downloadable product files can be overwritten through filename collisions CWE-73 - - 2026-07-06
CVE-2026-53647 FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint CWE-200 - - 2026-07-06
CVE-2026-53646 FOSSBilling: Client password reset token reuse allows persistent account takeover CWE-640 - - 2026-07-06
CVE-2026-53645 FOSSBilling's missing self-edit prevention in staff permission management allows persistent privilege escalation CWE-269 - - 2026-07-06
CVE-2026-53644 FOSSBilling's missing order-state validation allows clients to read and reset API key secrets for non-active orders CWE-639 - - 2026-07-06
CVE-2026-53643 FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints CWE-200 - - 2026-07-06
CVE-2026-53642 FOSSBilling: Unverified clients can access client-area pages when email confirmation is required CWE-863 - - 2026-07-06
CVE-2026-53641 FOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literal CWE-79 - - 2026-07-06
CVE-2026-53640 FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data CWE-200 - - 2026-07-06
CVE-2026-43928 FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpayment CWE-754 - - 2026-07-06
CVE-2026-43927 FOSSBilling has race condition in cart checkout that bypasses promo code usage limits CWE-367 - - 2026-07-06
CVE-2026-43925 FOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code use CWE-915 - - 2026-07-06
CVE-2026-43921 FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config serialization CWE-94 - - 2026-07-06
CVE-2026-43918 Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flows CWE-613 - - 2026-07-06
CVE-2026-42331 FOSSBilling missing authorization in guest Invoice API endpoints CWE-306 - - 2026-07-06
CVE-2026-33734 FOSSBilling has improper SQL neutralization in `Massmailer` recipient filters CWE-89 - - 2026-07-06
CVE-2026-42341 FOSSBilling has an unauthenticated payment bypass via IPN callback forgery CWE-306 - - 2026-07-06
CVE-2026-43920 FOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance execution CWE-306 - - 2026-06-25
CVE-2026-33543 FOSSBilling: Authentication bypass allows unauthenticated administrator creation CWE-288 - - 2026-06-24
CVE-2026-27708 FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access CWE-284 - - 2026-06-24
CVE-2026-23513 FOSSBilling: Broken Authorization in Client Transaction and Order Listings CWE-863 - - 2026-06-23
CVE-2025-64105 FOSSBilling: IDOR Vulnerability in Support Ticket Creation CWE-639 - - 2026-06-23
CVE-2026-27604 FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin Functions CWE-200 - - 2026-06-23
CVE-2026-28496 FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE CWE-1336 - - 2026-06-23
CVE-2026-43926 FOSSBilling's password reset confirmation endpoint lacks rate limiting CWE-204 - - 2026-06-04
CVE-2026-43924 FOSSBilling has an open redirect via administrator-configured redirect targets CWE-601 - - 2026-06-03
CVE-2026-40495 FOSSBilling version exposed via asset cache buster CWE-200 - - 2026-06-03

All 27 known CVE vulnerabilities affecting FOSSBilling with full Chinese analysis, references, and POCs where available.