Перейти к содержимому
Noroxi

Записи InvoicePlane

29 опубликованных записей вендора invoiceplane.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
13,8 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

29 записей
  • CVE-2024-56975
    39Наблюдать

    InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    invoiceplane · invoiceplane28 мар. 2025 г.

  • CVE-2025-67084
    39Наблюдать

    File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which

    КритическаяCVSS 9,9Эксплойта нетEPSS 0 %

    invoiceplane · invoiceplane15 янв. 2026 г.

  • CVE-2026-23491
    38Наблюдать

    InvoicePlane has Unauthenticated Path Traversal in Guest Controller

    КритическаяCVSS 9,3Proof of conceptEPSS 4 %

    invoiceplane · invoiceplane18 февр. 2026 г.

  • CVE-2026-25548
    36Наблюдать

    InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoning

    КритическаяCVSS 9,1Proof of conceptEPSS 1 %

    invoiceplane · invoiceplane18 февр. 2026 г.

  • CVE-2017-1000238
    35Наблюдать

    InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the w

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    invoiceplane · invoiceplane16 нояб. 2017 г.

  • CVE-2021-29024
    30Наблюдать

    In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    invoiceplane · invoiceplane17 мая 2021 г.

  • CVE-2026-24746
    30Наблюдать

    InvoicePlane has a Stored Cross-Site Scripting (XSS) issue

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    invoiceplane · invoiceplane18 февр. 2026 г.

  • CVE-2026-24744
    30Наблюдать

    InvoicePlane has a Stored Cross-Site Scripting (XSS) issue

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    invoiceplane · invoiceplane18 февр. 2026 г.

  • CVE-2026-24745
    30Наблюдать

    InvoicePlane has a Stored Cross-Site Scripting (XSS) issue

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    invoiceplane · invoiceplane18 февр. 2026 г.

  • CVE-2026-24743
    30Наблюдать

    InvoicePlane has a Stored Cross-Site Scripting (XSS) issue

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    invoiceplane · invoiceplane18 февр. 2026 г.

  • CVE-2025-67082
    26Наблюдать

    An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generati

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    invoiceplane · invoiceplane15 янв. 2026 г.

  • CVE-2024-12667
    25Наблюдать

    InvoicePlane view session expiration

    СредняяCVSS 6,3Эксплойта нетEPSS 1 %

    invoiceplane · invoiceplane16 дек. 2024 г.

  • CVE-2017-18217
    24Наблюдать

    An issue was discovered in InvoicePlane before 1.5.5.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    invoiceplane · invoiceplane5 мар. 2018 г.

  • CVE-2017-1000508
    24Наблюдать

    Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    invoiceplane · invoiceplane9 февр. 2018 г.

  • CVE-2018-12255
    24Наблюдать

    An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    invoiceplane · invoiceplane3 июл. 2018 г.

  • CVE-2023-23011
    24Наблюдать

    Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    invoiceplane · invoiceplane7 февр. 2023 г.

  • CVE-2021-29023
    21Наблюдать

    InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predic

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    invoiceplane · invoiceplane17 мая 2021 г.

  • CVE-2021-29022
    21Наблюдать

    In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    invoiceplane · invoiceplane10 мая 2021 г.

  • CVE-2025-67083
    21Наблюдать

    Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server.

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    invoiceplane · invoiceplane15 янв. 2026 г.

  • CVE-2019-7223
    21Наблюдать

    InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    invoiceplane · invoiceplane21 мар. 2019 г.

  • CVE-2024-12478
    21Наблюдать

    InvoicePlane 1 upload_file unrestricted upload

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    invoiceplane · invoiceplane16 дек. 2024 г.

  • CVE-2024-12362
    21Наблюдать

    InvoicePlane invoices.php download path traversal

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    invoiceplane · invoiceplane16 дек. 2024 г.

  • CVE-2017-1000239
    21Наблюдать

    InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious c

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    invoiceplane · invoiceplane16 нояб. 2017 г.

  • CVE-2026-26270
    21Наблюдать

    InvoicePlane has Stored Cross-Site Scripting Issue in Identifier Formatting

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    invoiceplane · invoiceplane18 февр. 2026 г.

  • CVE-2026-25594
    19Наблюдать

    InvoicePlane has Stored XSS via Family Name in Product Form

    СредняяCVSS 4,8Proof of conceptEPSS 0 %

    invoiceplane · invoiceplane18 февр. 2026 г.