Записи InvoicePlane
29 опубликованных записей вендора invoiceplane.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 13,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-613 Insufficient Session Expiration1
- CWE-616 Incomplete Identification of Uploaded File Variables (PHP)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
29 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-56975Эксплойта нет | InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_fileinvoiceplane · invoiceplane · CWE-434 | Критическая9,8 | — | 0,7 % | 28 мар. 2025 г. |
39Наблюдать | CVE-2025-67084Эксплойта нет | File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, whichinvoiceplane · invoiceplane · CWE-616 | Критическая9,9 | — | 0,5 % | 15 янв. 2026 г. |
38Наблюдать | CVE-2026-23491Proof of concept | InvoicePlane has Unauthenticated Path Traversal in Guest Controllerinvoiceplane · invoiceplane · CWE-22 | Критическая9,3 | — | 4,2 % | 18 февр. 2026 г. |
36Наблюдать | CVE-2026-25548Proof of concept | InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoninginvoiceplane · invoiceplane · CWE-94 | Критическая9,1 | — | 0,9 % | 18 февр. 2026 г. |
35Наблюдать | CVE-2017-1000238Эксплойта нет | InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the winvoiceplane · invoiceplane · CWE-434 | Высокая8,8 | — | 1,1 % | 16 нояб. 2017 г. |
30Наблюдать | CVE-2021-29024Эксплойта нет | In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download.invoiceplane · invoiceplane · CWE-552 | Высокая7,5 | — | 1,6 % | 17 мая 2021 г. |
30Наблюдать | CVE-2026-24746Эксплойта нет | InvoicePlane has a Stored Cross-Site Scripting (XSS) issueinvoiceplane · invoiceplane · CWE-79 | Высокая7,5 | — | 0,3 % | 18 февр. 2026 г. |
30Наблюдать | CVE-2026-24744Эксплойта нет | InvoicePlane has a Stored Cross-Site Scripting (XSS) issueinvoiceplane · invoiceplane · CWE-79 | Высокая7,5 | — | 0,2 % | 18 февр. 2026 г. |
30Наблюдать | CVE-2026-24745Эксплойта нет | InvoicePlane has a Stored Cross-Site Scripting (XSS) issueinvoiceplane · invoiceplane · CWE-79 | Высокая7,5 | — | 0,2 % | 18 февр. 2026 г. |
30Наблюдать | CVE-2026-24743Эксплойта нет | InvoicePlane has a Stored Cross-Site Scripting (XSS) issueinvoiceplane · invoiceplane · CWE-79 | Высокая7,5 | — | 0,2 % | 18 февр. 2026 г. |
26Наблюдать | CVE-2025-67082Эксплойта нет | An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generatiinvoiceplane · invoiceplane · CWE-89 | Средняя6,5 | — | 0,3 % | 15 янв. 2026 г. |
25Наблюдать | CVE-2024-12667Эксплойта нет | InvoicePlane view session expirationinvoiceplane · invoiceplane · CWE-613 | Средняя6,3 | — | 0,5 % | 16 дек. 2024 г. |
24Наблюдать | CVE-2017-18217Эксплойта нет | An issue was discovered in InvoicePlane before 1.5.5.invoiceplane · invoiceplane · CWE-79 | Средняя6,1 | — | 1,3 % | 5 мар. 2018 г. |
24Наблюдать | CVE-2017-1000508Эксплойта нет | Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in executioninvoiceplane · invoiceplane · CWE-79 | Средняя6,1 | — | 1,0 % | 9 февр. 2018 г. |
24Наблюдать | CVE-2018-12255Эксплойта нет | An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field.invoiceplane · invoiceplane · CWE-79 | Средняя6,1 | — | 0,7 % | 3 июл. 2018 г. |
24Наблюдать | CVE-2023-23011Эксплойта нет | Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.invoiceplane · invoiceplane · CWE-79 | Средняя6,1 | — | 0,5 % | 7 февр. 2023 г. |
21Наблюдать | CVE-2021-29023Эксплойта нет | InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predicinvoiceplane · invoiceplane · CWE-307 | Средняя5,3 | — | 1,2 % | 17 мая 2021 г. |
21Наблюдать | CVE-2021-29022Эксплойта нет | In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.invoiceplane · invoiceplane · CWE-434 | Средняя5,3 | — | 1,1 % | 10 мая 2021 г. |
21Наблюдать | CVE-2025-67083Эксплойта нет | Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server.invoiceplane · invoiceplane · CWE-22 | Средняя5,3 | — | 0,7 % | 15 янв. 2026 г. |
21Наблюдать | CVE-2019-7223Эксплойта нет | InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Createinvoiceplane · invoiceplane · CWE-79 | Средняя5,4 | — | 0,7 % | 21 мар. 2019 г. |
21Наблюдать | CVE-2024-12478Эксплойта нет | InvoicePlane 1 upload_file unrestricted uploadinvoiceplane · invoiceplane · CWE-284 | Средняя5,3 | — | 0,6 % | 16 дек. 2024 г. |
21Наблюдать | CVE-2024-12362Эксплойта нет | InvoicePlane invoices.php download path traversalinvoiceplane · invoiceplane · CWE-22 | Средняя5,3 | — | 0,6 % | 16 дек. 2024 г. |
21Наблюдать | CVE-2017-1000239Эксплойта нет | InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious cinvoiceplane · invoiceplane · CWE-79 | Средняя5,4 | — | 0,5 % | 16 нояб. 2017 г. |
21Наблюдать | CVE-2026-26270Эксплойта нет | InvoicePlane has Stored Cross-Site Scripting Issue in Identifier Formattinginvoiceplane · invoiceplane · CWE-79 | Средняя5,4 | — | 0,2 % | 18 февр. 2026 г. |
19Наблюдать | CVE-2026-25594Proof of concept | InvoicePlane has Stored XSS via Family Name in Product Forminvoiceplane · invoiceplane · CWE-79 | Средняя4,8 | — | 0,3 % | 18 февр. 2026 г. |
- CVE-2024-5697539Наблюдать
InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %invoiceplane · invoiceplane28 мар. 2025 г.
- CVE-2025-6708439Наблюдать
File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %invoiceplane · invoiceplane15 янв. 2026 г.
- CVE-2026-2349138Наблюдать
InvoicePlane has Unauthenticated Path Traversal in Guest Controller
КритическаяCVSS 9,3Proof of conceptEPSS 4 %invoiceplane · invoiceplane18 февр. 2026 г.
- CVE-2026-2554836Наблюдать
InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoning
КритическаяCVSS 9,1Proof of conceptEPSS 1 %invoiceplane · invoiceplane18 февр. 2026 г.
- CVE-2017-100023835Наблюдать
InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the w
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %invoiceplane · invoiceplane16 нояб. 2017 г.
- CVE-2021-2902430Наблюдать
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %invoiceplane · invoiceplane17 мая 2021 г.
- CVE-2026-2474630Наблюдать
InvoicePlane has a Stored Cross-Site Scripting (XSS) issue
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %invoiceplane · invoiceplane18 февр. 2026 г.
- CVE-2026-2474430Наблюдать
InvoicePlane has a Stored Cross-Site Scripting (XSS) issue
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %invoiceplane · invoiceplane18 февр. 2026 г.
- CVE-2026-2474530Наблюдать
InvoicePlane has a Stored Cross-Site Scripting (XSS) issue
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %invoiceplane · invoiceplane18 февр. 2026 г.
- CVE-2026-2474330Наблюдать
InvoicePlane has a Stored Cross-Site Scripting (XSS) issue
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %invoiceplane · invoiceplane18 февр. 2026 г.
- CVE-2025-6708226Наблюдать
An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generati
СредняяCVSS 6,5Эксплойта нетEPSS 0 %invoiceplane · invoiceplane15 янв. 2026 г.
- CVE-2024-1266725Наблюдать
InvoicePlane view session expiration
СредняяCVSS 6,3Эксплойта нетEPSS 1 %invoiceplane · invoiceplane16 дек. 2024 г.
- CVE-2017-1821724Наблюдать
An issue was discovered in InvoicePlane before 1.5.5.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %invoiceplane · invoiceplane5 мар. 2018 г.
- CVE-2017-100050824Наблюдать
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution
СредняяCVSS 6,1Эксплойта нетEPSS 1 %invoiceplane · invoiceplane9 февр. 2018 г.
- CVE-2018-1225524Наблюдать
An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %invoiceplane · invoiceplane3 июл. 2018 г.
- CVE-2023-2301124Наблюдать
Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %invoiceplane · invoiceplane7 февр. 2023 г.
- CVE-2021-2902321Наблюдать
InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predic
СредняяCVSS 5,3Эксплойта нетEPSS 1 %invoiceplane · invoiceplane17 мая 2021 г.
- CVE-2021-2902221Наблюдать
In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %invoiceplane · invoiceplane10 мая 2021 г.
- CVE-2025-6708321Наблюдать
Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %invoiceplane · invoiceplane15 янв. 2026 г.
- CVE-2019-722321Наблюдать
InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create
СредняяCVSS 5,4Эксплойта нетEPSS 1 %invoiceplane · invoiceplane21 мар. 2019 г.
- CVE-2024-1247821Наблюдать
InvoicePlane 1 upload_file unrestricted upload
СредняяCVSS 5,3Эксплойта нетEPSS 1 %invoiceplane · invoiceplane16 дек. 2024 г.
- CVE-2024-1236221Наблюдать
InvoicePlane invoices.php download path traversal
СредняяCVSS 5,3Эксплойта нетEPSS 1 %invoiceplane · invoiceplane16 дек. 2024 г.
- CVE-2017-100023921Наблюдать
InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious c
СредняяCVSS 5,4Эксплойта нетEPSS 0 %invoiceplane · invoiceplane16 нояб. 2017 г.
- CVE-2026-2627021Наблюдать
InvoicePlane has Stored Cross-Site Scripting Issue in Identifier Formatting
СредняяCVSS 5,4Эксплойта нетEPSS 0 %invoiceplane · invoiceplane18 февр. 2026 г.
- CVE-2026-2559419Наблюдать
InvoicePlane has Stored XSS via Family Name in Product Form
СредняяCVSS 4,8Proof of conceptEPSS 0 %invoiceplane · invoiceplane18 февр. 2026 г.