Fossbilling
by fossbilling
Source repositories
CVEs (39)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-43925 | Med | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in the client self-registration endpoint allows any visitor to assign themselves to an arbitrary client group during sign-up. Because… | ||
| CVE-2026-43921 | Hig | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code injection vulnerability in FOSSBilling's `Config::prettyPrintArrayToPHP()` method. When configuration values are updated, string values are written into… | ||
| CVE-2026-43918 | Hig | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/admin account is suspended or marked inactive, existing authenticated sessions are not invalidated. The session identity loaders in src/di.php (loggedin_client… | ||
| CVE-2026-42341 | Cri | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice… | ||
| CVE-2026-42331 | Hig | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an authorization check present in other invoice-related endpoints, allowing an unauthenticated user with knowledge of an invoice hash… | ||
| CVE-2026-33734 | Med | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injection vulnerability in the `Massmailer` module filter functionality. An authenticated administrator can supply crafted filter values when updating a mass email… | ||
| CVE-2026-43920 | Med | 0.00 | — | 0.01 | Jun 26, 2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was accessible without authentication, which allowed unauthenticated remote users to trigger update patch routines that… | ||
| CVE-2023-4005 | Cri | 0.00 | 9.8 | 0.00 | Jul 31, 2023 | Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5. | ||
| CVE-2023-3568 | Med | 0.00 | 6.3 | 0.00 | Jul 10, 2023 | Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | ||
| CVE-2023-3521 | Med | 0.00 | 6.1 | 0.01 | Jul 6, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4. | ||
| CVE-2023-3493 | Hig | 0.00 | 8.0 | 0.01 | Jun 30, 2023 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository fossbilling/fossbilling prior to 0.5.3. | ||
| CVE-2023-3491 | Hig | 0.00 | 8.8 | 0.01 | Jun 30, 2023 | Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3. | ||
| CVE-2023-3490 | Cri | 0.00 | 9.8 | 0.01 | Jun 30, 2023 | SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3. | ||
| CVE-2023-3394 | Med | 0.00 | 5.4 | 0.01 | Jun 23, 2023 | Session Fixation in GitHub repository fossbilling/fossbilling prior to 0.5.1. | ||
| CVE-2023-3393 | Hig | 0.00 | 7.2 | 0.01 | Jun 23, 2023 | Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1. | ||
| CVE-2023-3230 | Hig | 0.00 | 7.5 | 0.00 | Jun 14, 2023 | Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0. | ||
| CVE-2023-3229 | Med | 0.00 | 6.5 | 0.01 | Jun 14, 2023 | Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0. | ||
| CVE-2023-3228 | Med | 0.00 | 5.7 | 0.00 | Jun 14, 2023 | Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0. | ||
| CVE-2023-3227 | Med | 0.00 | 5.7 | 0.00 | Jun 14, 2023 | Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0. |
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in the client self-registration endpoint allows any visitor to assign themselves to an arbitrary client group during sign-up. Because…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code injection vulnerability in FOSSBilling's `Config::prettyPrintArrayToPHP()` method. When configuration values are updated, string values are written into…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/admin account is suspended or marked inactive, existing authenticated sessions are not invalidated. The session identity loaders in src/di.php (loggedin_client…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an authorization check present in other invoice-related endpoints, allowing an unauthenticated user with knowledge of an invoice hash…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injection vulnerability in the `Massmailer` module filter functionality. An authenticated administrator can supply crafted filter values when updating a mass email…
- risk 0.00cvss —epss 0.01
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was accessible without authentication, which allowed unauthenticated remote users to trigger update patch routines that…
- risk 0.00cvss 9.8epss 0.00
Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.
- risk 0.00cvss 6.3epss 0.00
Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.
- risk 0.00cvss 8.0epss 0.01
Improper Neutralization of Formula Elements in a CSV File in GitHub repository fossbilling/fossbilling prior to 0.5.3.
- risk 0.00cvss 8.8epss 0.01
Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.
- risk 0.00cvss 9.8epss 0.01
SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.
- risk 0.00cvss 5.4epss 0.01
Session Fixation in GitHub repository fossbilling/fossbilling prior to 0.5.1.
- risk 0.00cvss 7.2epss 0.01
Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1.
- risk 0.00cvss 7.5epss 0.00
Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0.
- risk 0.00cvss 6.5epss 0.01
Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0.
- risk 0.00cvss 5.7epss 0.00
Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0.
- risk 0.00cvss 5.7epss 0.00
Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0.
Page 2 of 2