Vendor CVEs
fossbilling
All CVEs
39 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-27604 | Cri | 0.58 | — | 0.00 | Jun 23, 2026 | FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` endpoints. Because `system` resolves to the… | ||
| CVE-2026-28496 | Cri | 0.56 | — | 0.18 | Jun 23, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template Injection (SSTI) vulnerability in the template rendering system. Administrators with access to features that render Twig templates (email templates, mass… | ||
| CVE-2026-33543 | Cri | 0.53 | — | 0.00 | Jun 24, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API endpoint, /api/guest/staff/create, intended for initial administrator bootstrap. Due to a flawed admin-existence check, the endpoint remains usable after an… | ||
| CVE-2026-40495 | Med | 0.45 | — | 0.00 | Jun 3, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system version through asset cache buster parameters in HTML output, bypassing the `hide_version_public` security setting. The FOSSBilling version is embedded in the… | ||
| CVE-2026-43926 | Med | 0.41 | — | 0.00 | Jun 4, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset confirmation endpoint `/client/reset-password-confirm/:hash` is handled by a non-API controller and is not covered by FOSSBilling's rate limiter, which only… | ||
| CVE-2026-27708 | Hig | 0.39 | — | 0.00 | Jun 24, 2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method accepts an order_id parameter and fetches the associated order without verifying the authenticated client owns it, potentially… | ||
| CVE-2026-23513 | Hig | 0.39 | — | 0.00 | Jun 23, 2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-construction flaw in client list endpoints allowed authenticated clients to bypass tenant scoping and retrieve other clients’ data. Details In… | ||
| CVE-2026-43924 | Med | 0.31 | — | 0.00 | Jun 3, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module does not validate the URL scheme of administrator-configured destination URLs before storing or issuing redirects. This allows arbitrary external URLs to be… | ||
| CVE-2025-64105 | Med | 0.26 | — | 0.00 | Jun 23, 2026 | FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online service businesses. Versions 0.6.21 through 0.7.2 are vulnerable to IDOR through the support ticket creation workflow. By manipulating rel_id when… | ||
| CVE-2026-53648 | Med | 0.00 | — | 0.00 | Jul 7, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product files are stored using a deterministic filename-derived path. When an administrator uploads a file for a downloadable product, FOSSBilling stores the file as… | ||
| CVE-2026-53647 | Med | 0.00 | — | 0.00 | Jul 7, 2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endpoint is accessible without authentication. Any caller with a valid API key can retrieve all custom configuration parameters… | ||
| CVE-2026-53646 | Hig | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when a `ClientPasswordReset` record already exists for a client (from a previous unexpired reset request), subsequent calls to the `reset_password` guest API endpoint reuse… | ||
| CVE-2026-53645 | Hig | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow a low-privileged staff account to grant arbitrary module permissions to itself through the admin API, resulting in persistent privilege escalation. A staff user that only has… | ||
| CVE-2026-53644 | Hig | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.5.3 through 0.7.2 allow authenticated clients to both read and reset API key service secrets for orders that are no longer in an `active` state (e.g., `suspended`, `canceled`). The root cause is… | ||
| CVE-2026-53643 | Hig | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unauthorized actions via admin API endpoints. The root cause is a combination of the `can_always_access` module flag (which grants all… | ||
| CVE-2026-53642 | Med | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when the "Require Email Confirmation" setting is enabled, a logged-in client with an unverified email address (`email_approved = 0`) can access all client-area pages (e.g.… | ||
| CVE-2026-53641 | Med | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a stored cross-site scripting (XSS) vulnerability in the client-facing email history views of FOSSBilling. Email HTML content (`content_html`) is rendered into a JavaScript… | ||
| CVE-2026-53640 | Low | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff accounts may read sensitive data via admin API endpoints that lack permission checks. While sibling write endpoints correctly enforce fine-grained permissions,… | ||
| CVE-2026-43928 | Low | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment adapter accepts PayPal IPN callbacks and credits the IPN-supplied amount (`mc_gross`) to the client's balance without validating it against the invoice total.… | ||
| CVE-2026-43927 | Med | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, a race condition in the cart checkout flow allows an authenticated client to apply a promo code beyond its configured maximum uses. By sending concurrent checkout requests before any… | ||
| CVE-2026-43925 | Med | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in the client self-registration endpoint allows any visitor to assign themselves to an arbitrary client group during sign-up. Because… | ||
| CVE-2026-43921 | Hig | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code injection vulnerability in FOSSBilling's `Config::prettyPrintArrayToPHP()` method. When configuration values are updated, string values are written into… | ||
| CVE-2026-43918 | Hig | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/admin account is suspended or marked inactive, existing authenticated sessions are not invalidated. The session identity loaders in src/di.php (loggedin_client… | ||
| CVE-2026-42341 | Cri | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice… | ||
| CVE-2026-42331 | Hig | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an authorization check present in other invoice-related endpoints, allowing an unauthenticated user with knowledge of an invoice hash… | ||
| CVE-2026-33734 | Med | 0.00 | — | 0.00 | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injection vulnerability in the `Massmailer` module filter functionality. An authenticated administrator can supply crafted filter values when updating a mass email… | ||
| CVE-2026-43920 | Med | 0.00 | — | 0.01 | Jun 26, 2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was accessible without authentication, which allowed unauthenticated remote users to trigger update patch routines that… | ||
| CVE-2023-4005 | Cri | 0.00 | 9.8 | 0.00 | Jul 31, 2023 | Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5. | ||
| CVE-2023-3568 | Med | 0.00 | 6.3 | 0.00 | Jul 10, 2023 | Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | ||
| CVE-2023-3521 | Med | 0.00 | 6.1 | 0.01 | Jul 6, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4. | ||
| CVE-2023-3493 | Hig | 0.00 | 8.0 | 0.01 | Jun 30, 2023 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository fossbilling/fossbilling prior to 0.5.3. | ||
| CVE-2023-3491 | Hig | 0.00 | 8.8 | 0.01 | Jun 30, 2023 | Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3. | ||
| CVE-2023-3490 | Cri | 0.00 | 9.8 | 0.01 | Jun 30, 2023 | SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3. | ||
| CVE-2023-3394 | Med | 0.00 | 5.4 | 0.01 | Jun 23, 2023 | Session Fixation in GitHub repository fossbilling/fossbilling prior to 0.5.1. | ||
| CVE-2023-3393 | Hig | 0.00 | 7.2 | 0.01 | Jun 23, 2023 | Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1. | ||
| CVE-2023-3230 | Hig | 0.00 | 7.5 | 0.00 | Jun 14, 2023 | Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0. | ||
| CVE-2023-3229 | Med | 0.00 | 6.5 | 0.01 | Jun 14, 2023 | Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0. | ||
| CVE-2023-3228 | Med | 0.00 | 5.7 | 0.00 | Jun 14, 2023 | Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0. | ||
| CVE-2023-3227 | Med | 0.00 | 5.7 | 0.00 | Jun 14, 2023 | Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0. |
- risk 0.58cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` endpoints. Because `system` resolves to the…
- risk 0.56cvss —epss 0.18
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template Injection (SSTI) vulnerability in the template rendering system. Administrators with access to features that render Twig templates (email templates, mass…
- risk 0.53cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API endpoint, /api/guest/staff/create, intended for initial administrator bootstrap. Due to a flawed admin-existence check, the endpoint remains usable after an…
- risk 0.45cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system version through asset cache buster parameters in HTML output, bypassing the `hide_version_public` security setting. The FOSSBilling version is embedded in the…
- risk 0.41cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset confirmation endpoint `/client/reset-password-confirm/:hash` is handled by a non-API controller and is not covered by FOSSBilling's rate limiter, which only…
- risk 0.39cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method accepts an order_id parameter and fetches the associated order without verifying the authenticated client owns it, potentially…
- risk 0.39cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-construction flaw in client list endpoints allowed authenticated clients to bypass tenant scoping and retrieve other clients’ data. Details In…
- risk 0.31cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module does not validate the URL scheme of administrator-configured destination URLs before storing or issuing redirects. This allows arbitrary external URLs to be…
- risk 0.26cvss —epss 0.00
FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online service businesses. Versions 0.6.21 through 0.7.2 are vulnerable to IDOR through the support ticket creation workflow. By manipulating rel_id when…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product files are stored using a deterministic filename-derived path. When an administrator uploads a file for a downloadable product, FOSSBilling stores the file as…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endpoint is accessible without authentication. Any caller with a valid API key can retrieve all custom configuration parameters…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when a `ClientPasswordReset` record already exists for a client (from a previous unexpired reset request), subsequent calls to the `reset_password` guest API endpoint reuse…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow a low-privileged staff account to grant arbitrary module permissions to itself through the admin API, resulting in persistent privilege escalation. A staff user that only has…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Versions 0.5.3 through 0.7.2 allow authenticated clients to both read and reset API key service secrets for orders that are no longer in an `active` state (e.g., `suspended`, `canceled`). The root cause is…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unauthorized actions via admin API endpoints. The root cause is a combination of the `can_always_access` module flag (which grants all…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when the "Require Email Confirmation" setting is enabled, a logged-in client with an unverified email address (`email_approved = 0`) can access all client-area pages (e.g.…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a stored cross-site scripting (XSS) vulnerability in the client-facing email history views of FOSSBilling. Email HTML content (`content_html`) is rendered into a JavaScript…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff accounts may read sensitive data via admin API endpoints that lack permission checks. While sibling write endpoints correctly enforce fine-grained permissions,…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment adapter accepts PayPal IPN callbacks and credits the IPN-supplied amount (`mc_gross`) to the client's balance without validating it against the invoice total.…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, a race condition in the cart checkout flow allows an authenticated client to apply a promo code beyond its configured maximum uses. By sending concurrent checkout requests before any…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in the client self-registration endpoint allows any visitor to assign themselves to an arbitrary client group during sign-up. Because…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code injection vulnerability in FOSSBilling's `Config::prettyPrintArrayToPHP()` method. When configuration values are updated, string values are written into…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/admin account is suspended or marked inactive, existing authenticated sessions are not invalidated. The session identity loaders in src/di.php (loggedin_client…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an authorization check present in other invoice-related endpoints, allowing an unauthenticated user with knowledge of an invoice hash…
- risk 0.00cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injection vulnerability in the `Massmailer` module filter functionality. An authenticated administrator can supply crafted filter values when updating a mass email…
- risk 0.00cvss —epss 0.01
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was accessible without authentication, which allowed unauthenticated remote users to trigger update patch routines that…
- risk 0.00cvss 9.8epss 0.00
Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.
- risk 0.00cvss 6.3epss 0.00
Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.
- risk 0.00cvss 8.0epss 0.01
Improper Neutralization of Formula Elements in a CSV File in GitHub repository fossbilling/fossbilling prior to 0.5.3.
- risk 0.00cvss 8.8epss 0.01
Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.
- risk 0.00cvss 9.8epss 0.01
SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.
- risk 0.00cvss 5.4epss 0.01
Session Fixation in GitHub repository fossbilling/fossbilling prior to 0.5.1.
- risk 0.00cvss 7.2epss 0.01
Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1.
- risk 0.00cvss 7.5epss 0.00
Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0.
- risk 0.00cvss 6.5epss 0.01
Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0.
- risk 0.00cvss 5.7epss 0.00
Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0.
- risk 0.00cvss 5.7epss 0.00
Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0.