VYPR

Invoiceplane

by Invoiceplane

Source repositories

CVEs (29)

  • CVE-2026-24743MedFeb 18, 2026
    risk 0.00cvss 5.7epss 0.00

    InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the upload Invoice Logo functions of InvoicePlane version 1.7.0. The Upload Invoice Logo function allows the…

  • CVE-2026-24746MedFeb 18, 2026
    risk 0.00cvss 5.7epss 0.00

    InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the Edit Quotes functions of InvoicePlane version 1.7.0. In the Editing Quotes function, the application does not…

  • CVE-2026-23491HigFeb 18, 2026
    risk 0.00cvss 7.5epss 0.01

    InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vulnerability exists in the `get_file` method of the `Guest` module's `Get` controller in InvoicePlane up to and including through 1.6.3. The vulnerability allows…

  • CVE-2025-64012MedDec 16, 2025
    risk 0.00cvss 4.3epss 0.00

    InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. The invoices/view handler fails to verify ownership before returning invoice data.

  • CVE-2024-56975CriMar 28, 2025
    risk 0.00cvss 9.8epss 0.01

    InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller.

  • CVE-2024-12478MedDec 16, 2024
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the function upload_file of the file /index.php/upload/upload_file/1/1. The manipulation of the argument file leads to unrestricted upload. The attack can be…

  • CVE-2024-12362MedDec 16, 2024
    risk 0.00cvss 4.3epss 0.01

    A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic. This affects the function download of the file invoices.php. The manipulation of the argument invoice leads to path traversal. It is possible to initiate the attack remotely. The…

  • CVE-2017-18217MedMar 5, 2018
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and…

  • CVE-2017-1000508MedFeb 9, 2018
    risk 0.00cvss 6.1epss 0.01

    Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later.

Page 2 of 2