All 3 CVE vulnerabilities found in invoiceninja, with AI-generated Chinese analysis, references, and POCs.
Vendor: n/a
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-33742 | Invoice Ninja has Stored XSS via Markdown HTML Injection in Product Notes CWE-79 | 5.4 | Medium | 2026-03-26 |
| CVE-2026-33628 | Invoice Ninja Denylist Bypass may Lead to Stored XSS via Invoice Line Items CWE-79 | 5.4 | Medium | 2026-03-26 |
| CVE-2026-0649 | invoiceninja Migration Import Import.php copy server-side request forgery CWE-918 | 4.7 | Medium | 2026-01-07 |
All 3 known CVE vulnerabilities affecting invoiceninja with full Chinese analysis, references, and POCs where available.