Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

fossbilling — Vulnerabilities & Security Advisories 38

Browse all 38 CVE security advisories affecting fossbilling. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FOSSBilling serves as an open-source billing and invoicing platform for web hosting and SaaS businesses. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting (XSS), privilege escalation flaws, and insecure direct object references. The platform's 11 recorded CVEs highlight recurring issues in input validation, access control, and session management. While no major public security incidents have been documented, the consistent pattern of vulnerabilities suggests developers should implement strict input sanitization, enforce proper authentication mechanisms, and regularly update the system to mitigate potential exploitation risks.

Top products by fossbilling: FOSSBilling fossbilling/fossbilling
CVE ID Title CVSS Severity Published
CVE-2026-53648 FOSSBilling: Downloadable product files can be overwritten through filename collisions — FOSSBilling CWE-73 - - 2026-07-06
CVE-2026-53647 FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint — FOSSBilling CWE-200 - - 2026-07-06
CVE-2026-53646 FOSSBilling: Client password reset token reuse allows persistent account takeover — FOSSBilling CWE-640 - - 2026-07-06
CVE-2026-53645 FOSSBilling's missing self-edit prevention in staff permission management allows persistent privilege escalation — FOSSBilling CWE-269 - - 2026-07-06
CVE-2026-53644 FOSSBilling's missing order-state validation allows clients to read and reset API key secrets for non-active orders — FOSSBilling CWE-639 - - 2026-07-06
CVE-2026-53643 FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints — FOSSBilling CWE-200 - - 2026-07-06
CVE-2026-53642 FOSSBilling: Unverified clients can access client-area pages when email confirmation is required — FOSSBilling CWE-863 - - 2026-07-06
CVE-2026-53641 FOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literal — FOSSBilling CWE-79 - - 2026-07-06
CVE-2026-53640 FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data — FOSSBilling CWE-200 - - 2026-07-06
CVE-2026-43928 FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpayment — FOSSBilling CWE-754 - - 2026-07-06
CVE-2026-43927 FOSSBilling has race condition in cart checkout that bypasses promo code usage limits — FOSSBilling CWE-367 - - 2026-07-06
CVE-2026-43925 FOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code use — FOSSBilling CWE-915 - - 2026-07-06
CVE-2026-43921 FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config serialization — FOSSBilling CWE-94 - - 2026-07-06
CVE-2026-43918 Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flows — FOSSBilling CWE-613 - - 2026-07-06
CVE-2026-42331 FOSSBilling missing authorization in guest Invoice API endpoints — FOSSBilling CWE-306 - - 2026-07-06
CVE-2026-33734 FOSSBilling has improper SQL neutralization in `Massmailer` recipient filters — FOSSBilling CWE-89 - - 2026-07-06
CVE-2026-42341 FOSSBilling has an unauthenticated payment bypass via IPN callback forgery — FOSSBilling CWE-306 - - 2026-07-06
CVE-2026-43920 FOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance execution — FOSSBilling CWE-306 - - 2026-06-25
CVE-2026-33543 FOSSBilling: Authentication bypass allows unauthenticated administrator creation — FOSSBilling CWE-288 - - 2026-06-24
CVE-2026-27708 FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access — FOSSBilling CWE-284 - - 2026-06-24
CVE-2026-23513 FOSSBilling: Broken Authorization in Client Transaction and Order Listings — FOSSBilling CWE-863 - - 2026-06-23
CVE-2025-64105 FOSSBilling: IDOR Vulnerability in Support Ticket Creation — FOSSBilling CWE-639 - - 2026-06-23
CVE-2026-27604 FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin Functions — FOSSBilling CWE-200 - - 2026-06-23
CVE-2026-28496 FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE — FOSSBilling CWE-1336 - - 2026-06-23
CVE-2026-43926 FOSSBilling's password reset confirmation endpoint lacks rate limiting — FOSSBilling CWE-204 - - 2026-06-04
CVE-2026-43924 FOSSBilling has an open redirect via administrator-configured redirect targets — FOSSBilling CWE-601 - - 2026-06-03
CVE-2026-40495 FOSSBilling version exposed via asset cache buster — FOSSBilling CWE-200 - - 2026-06-03
CVE-2023-4005 Insufficient Session Expiration in fossbilling/fossbilling — fossbilling/fossbilling CWE-613 8.8 - 2023-07-31
CVE-2023-3521 Cross-site Scripting (XSS) - Reflected in fossbilling/fossbilling — fossbilling/fossbilling CWE-79 5.4 - 2023-07-06
CVE-2023-3493 Improper Neutralization of Formula Elements in a CSV File in fossbilling/fossbilling — fossbilling/fossbilling CWE-1236 8.0 - 2023-06-30

This page lists every published CVE security advisory associated with fossbilling. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.