VYPR

Vendor CVEs

fossbilling

All CVEs

39 total · sorted by risk
  • CVE-2026-27604CriJun 23, 2026
    risk 0.58cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` endpoints. Because `system` resolves to the…

  • CVE-2026-28496CriJun 23, 2026
    risk 0.56cvss epss 0.18

    FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template Injection (SSTI) vulnerability in the template rendering system. Administrators with access to features that render Twig templates (email templates, mass…

  • CVE-2026-33543CriJun 24, 2026
    risk 0.53cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API endpoint, /api/guest/staff/create, intended for initial administrator bootstrap. Due to a flawed admin-existence check, the endpoint remains usable after an…

  • CVE-2026-40495MedJun 3, 2026
    risk 0.45cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system version through asset cache buster parameters in HTML output, bypassing the `hide_version_public` security setting. The FOSSBilling version is embedded in the…

  • CVE-2026-43926MedJun 4, 2026
    risk 0.41cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset confirmation endpoint `/client/reset-password-confirm/:hash` is handled by a non-API controller and is not covered by FOSSBilling's rate limiter, which only…

  • CVE-2026-27708HigJun 24, 2026
    risk 0.39cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method accepts an order_id parameter and fetches the associated order without verifying the authenticated client owns it, potentially…

  • CVE-2026-23513HigJun 23, 2026
    risk 0.39cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-construction flaw in client list endpoints allowed authenticated clients to bypass tenant scoping and retrieve other clients’ data. Details In…

  • CVE-2026-43924MedJun 3, 2026
    risk 0.31cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module does not validate the URL scheme of administrator-configured destination URLs before storing or issuing redirects. This allows arbitrary external URLs to be…

  • CVE-2025-64105MedJun 23, 2026
    risk 0.26cvss epss 0.00

    FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online service businesses. Versions 0.6.21 through 0.7.2 are vulnerable to IDOR through the support ticket creation workflow. By manipulating rel_id when…

  • CVE-2026-53648MedJul 7, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product files are stored using a deterministic filename-derived path. When an administrator uploads a file for a downloadable product, FOSSBilling stores the file as…

  • CVE-2026-53647MedJul 7, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endpoint is accessible without authentication. Any caller with a valid API key can retrieve all custom configuration parameters…

  • CVE-2026-53646HigJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when a `ClientPasswordReset` record already exists for a client (from a previous unexpired reset request), subsequent calls to the `reset_password` guest API endpoint reuse…

  • CVE-2026-53645HigJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow a low-privileged staff account to grant arbitrary module permissions to itself through the admin API, resulting in persistent privilege escalation. A staff user that only has…

  • CVE-2026-53644HigJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Versions 0.5.3 through 0.7.2 allow authenticated clients to both read and reset API key service secrets for orders that are no longer in an `active` state (e.g., `suspended`, `canceled`). The root cause is…

  • CVE-2026-53643HigJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unauthorized actions via admin API endpoints. The root cause is a combination of the `can_always_access` module flag (which grants all…

  • CVE-2026-53642MedJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when the "Require Email Confirmation" setting is enabled, a logged-in client with an unverified email address (`email_approved = 0`) can access all client-area pages (e.g.…

  • CVE-2026-53641MedJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a stored cross-site scripting (XSS) vulnerability in the client-facing email history views of FOSSBilling. Email HTML content (`content_html`) is rendered into a JavaScript…

  • CVE-2026-53640LowJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff accounts may read sensitive data via admin API endpoints that lack permission checks. While sibling write endpoints correctly enforce fine-grained permissions,…

  • CVE-2026-43928LowJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment adapter accepts PayPal IPN callbacks and credits the IPN-supplied amount (`mc_gross`) to the client's balance without validating it against the invoice total.…

  • CVE-2026-43927MedJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, a race condition in the cart checkout flow allows an authenticated client to apply a promo code beyond its configured maximum uses. By sending concurrent checkout requests before any…

  • CVE-2026-43925MedJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in the client self-registration endpoint allows any visitor to assign themselves to an arbitrary client group during sign-up. Because…

  • CVE-2026-43921HigJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code injection vulnerability in FOSSBilling's `Config::prettyPrintArrayToPHP()` method. When configuration values are updated, string values are written into…

  • CVE-2026-43918HigJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/admin account is suspended or marked inactive, existing authenticated sessions are not invalidated. The session identity loaders in src/di.php (loggedin_client…

  • CVE-2026-42341CriJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice…

  • CVE-2026-42331HigJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an authorization check present in other invoice-related endpoints, allowing an unauthenticated user with knowledge of an invoice hash…

  • CVE-2026-33734MedJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injection vulnerability in the `Massmailer` module filter functionality. An authenticated administrator can supply crafted filter values when updating a mass email…

  • CVE-2026-43920MedJun 26, 2026
    risk 0.00cvss epss 0.01

    FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was accessible without authentication, which allowed unauthenticated remote users to trigger update patch routines that…

  • CVE-2023-4005CriJul 31, 2023
    risk 0.00cvss 9.8epss 0.00

    Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.

  • CVE-2023-3568MedJul 10, 2023
    risk 0.00cvss 6.3epss 0.00

    Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

  • CVE-2023-3521MedJul 6, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.

  • CVE-2023-3493HigJun 30, 2023
    risk 0.00cvss 8.0epss 0.01

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository fossbilling/fossbilling prior to 0.5.3.

  • CVE-2023-3491HigJun 30, 2023
    risk 0.00cvss 8.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.

  • CVE-2023-3490CriJun 30, 2023
    risk 0.00cvss 9.8epss 0.01

    SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.

  • CVE-2023-3394MedJun 23, 2023
    risk 0.00cvss 5.4epss 0.01

    Session Fixation in GitHub repository fossbilling/fossbilling prior to 0.5.1.

  • CVE-2023-3393HigJun 23, 2023
    risk 0.00cvss 7.2epss 0.01

    Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1.

  • CVE-2023-3230HigJun 14, 2023
    risk 0.00cvss 7.5epss 0.00

    Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0.

  • CVE-2023-3229MedJun 14, 2023
    risk 0.00cvss 6.5epss 0.01

    Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0.

  • CVE-2023-3228MedJun 14, 2023
    risk 0.00cvss 5.7epss 0.00

    Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0.

  • CVE-2023-3227MedJun 14, 2023
    risk 0.00cvss 5.7epss 0.00

    Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0.