İçeriğe atla
Noroxi

InvoicePlane kayıtları

invoiceplane üreticisine ait 29 yayımlanmış kayıt.

Tüm kayıtlar

29 kayıt
  • CVE-2024-56975
    39İzleyin

    InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file

    KritikCVSS 9,8İstismar yokEPSS %1

    invoiceplane · invoiceplane28 Mar 2025

  • CVE-2025-67084
    39İzleyin

    File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which

    KritikCVSS 9,9İstismar yokEPSS %0

    invoiceplane · invoiceplane15 Oca 2026

  • CVE-2026-23491
    38İzleyin

    InvoicePlane has Unauthenticated Path Traversal in Guest Controller

    KritikCVSS 9,3Kavram kanıtıEPSS %4

    invoiceplane · invoiceplane18 Şub 2026

  • CVE-2026-25548
    36İzleyin

    InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoning

    KritikCVSS 9,1Kavram kanıtıEPSS %1

    invoiceplane · invoiceplane18 Şub 2026

  • InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the w

    YüksekCVSS 8,8İstismar yokEPSS %1

    invoiceplane · invoiceplane16 Kas 2017

  • CVE-2021-29024
    30İzleyin

    In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download.

    YüksekCVSS 7,5İstismar yokEPSS %2

    invoiceplane · invoiceplane17 May 2021

  • CVE-2026-24746
    30İzleyin

    InvoicePlane has a Stored Cross-Site Scripting (XSS) issue

    YüksekCVSS 7,5İstismar yokEPSS %0

    invoiceplane · invoiceplane18 Şub 2026

  • CVE-2026-24744
    30İzleyin

    InvoicePlane has a Stored Cross-Site Scripting (XSS) issue

    YüksekCVSS 7,5İstismar yokEPSS %0

    invoiceplane · invoiceplane18 Şub 2026

  • CVE-2026-24745
    30İzleyin

    InvoicePlane has a Stored Cross-Site Scripting (XSS) issue

    YüksekCVSS 7,5İstismar yokEPSS %0

    invoiceplane · invoiceplane18 Şub 2026

  • CVE-2026-24743
    30İzleyin

    InvoicePlane has a Stored Cross-Site Scripting (XSS) issue

    YüksekCVSS 7,5İstismar yokEPSS %0

    invoiceplane · invoiceplane18 Şub 2026

  • CVE-2025-67082
    26İzleyin

    An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generati

    OrtaCVSS 6,5İstismar yokEPSS %0

    invoiceplane · invoiceplane15 Oca 2026

  • CVE-2024-12667
    25İzleyin

    InvoicePlane view session expiration

    OrtaCVSS 6,3İstismar yokEPSS %1

    invoiceplane · invoiceplane16 Ara 2024

  • CVE-2017-18217
    24İzleyin

    An issue was discovered in InvoicePlane before 1.5.5.

    OrtaCVSS 6,1İstismar yokEPSS %1

    invoiceplane · invoiceplane5 Mar 2018

  • Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution

    OrtaCVSS 6,1İstismar yokEPSS %1

    invoiceplane · invoiceplane9 Şub 2018

  • CVE-2018-12255
    24İzleyin

    An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field.

    OrtaCVSS 6,1İstismar yokEPSS %1

    invoiceplane · invoiceplane3 Tem 2018

  • CVE-2023-23011
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.

    OrtaCVSS 6,1İstismar yokEPSS %1

    invoiceplane · invoiceplane7 Şub 2023

  • CVE-2021-29023
    21İzleyin

    InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predic

    OrtaCVSS 5,3İstismar yokEPSS %1

    invoiceplane · invoiceplane17 May 2021

  • CVE-2021-29022
    21İzleyin

    In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.

    OrtaCVSS 5,3İstismar yokEPSS %1

    invoiceplane · invoiceplane10 May 2021

  • CVE-2025-67083
    21İzleyin

    Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server.

    OrtaCVSS 5,3İstismar yokEPSS %1

    invoiceplane · invoiceplane15 Oca 2026

  • CVE-2019-7223
    21İzleyin

    InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create

    OrtaCVSS 5,4İstismar yokEPSS %1

    invoiceplane · invoiceplane21 Mar 2019

  • CVE-2024-12478
    21İzleyin

    InvoicePlane 1 upload_file unrestricted upload

    OrtaCVSS 5,3İstismar yokEPSS %1

    invoiceplane · invoiceplane16 Ara 2024

  • CVE-2024-12362
    21İzleyin

    InvoicePlane invoices.php download path traversal

    OrtaCVSS 5,3İstismar yokEPSS %1

    invoiceplane · invoiceplane16 Ara 2024

  • InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious c

    OrtaCVSS 5,4İstismar yokEPSS %0

    invoiceplane · invoiceplane16 Kas 2017

  • CVE-2026-26270
    21İzleyin

    InvoicePlane has Stored Cross-Site Scripting Issue in Identifier Formatting

    OrtaCVSS 5,4İstismar yokEPSS %0

    invoiceplane · invoiceplane18 Şub 2026

  • CVE-2026-25594
    19İzleyin

    InvoicePlane has Stored XSS via Family Name in Product Form

    OrtaCVSS 4,8Kavram kanıtıEPSS %0

    invoiceplane · invoiceplane18 Şub 2026