Medium severity6.0NVD Advisory· Published Sep 25, 2026
CVE-2026-54790
CVE-2026-54790
Description
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores an administrator-controlled custom_field_table value without validating it against the allowed custom-field table names. Mdl_custom_fields::used() later concatenates that stored value into the FROM table and WHERE column identifier positions, so opening the custom-field edit form executes a second-order SQL injection. The injection can query arbitrary schema data and can cause application errors or denial of service. This issue is fixed in version 1.7.2.
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.