VYPR

Invoiceplane

by Invoiceplane

Source repositories

CVEs (44)

  • CVE-2025-64012MedDec 16, 2025
    risk 0.00cvss 4.3epss 0.00

    InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. The invoices/view handler fails to verify ownership before returning invoice data.

  • CVE-2024-56975CriMar 28, 2025
    risk 0.00cvss 9.8epss 0.01

    InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller.

  • CVE-2024-12478MedDec 16, 2024
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the function upload_file of the file /index.php/upload/upload_file/1/1. The manipulation of the argument file leads to unrestricted upload. The attack can be…

  • CVE-2024-12362MedDec 16, 2024
    risk 0.00cvss 4.3epss 0.01

    A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic. This affects the function download of the file invoices.php. The manipulation of the argument invoice leads to path traversal. It is possible to initiate the attack remotely. The…

Page 3 of 3