InvoicePlane kayıtları
invoiceplane üreticisine ait 29 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %13,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-613 Insufficient Session Expiration1
- CWE-616 Incomplete Identification of Uploaded File Variables (PHP)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
29 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-56975İstismar yok | InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_fileinvoiceplane · invoiceplane · CWE-434 | Kritik9,8 | — | %0,7 | 28 Mar 2025 |
39İzleyin | CVE-2025-67084İstismar yok | File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, whichinvoiceplane · invoiceplane · CWE-616 | Kritik9,9 | — | %0,5 | 15 Oca 2026 |
38İzleyin | CVE-2026-23491Kavram kanıtı | InvoicePlane has Unauthenticated Path Traversal in Guest Controllerinvoiceplane · invoiceplane · CWE-22 | Kritik9,3 | — | %4,2 | 18 Şub 2026 |
36İzleyin | CVE-2026-25548Kavram kanıtı | InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoninginvoiceplane · invoiceplane · CWE-94 | Kritik9,1 | — | %0,9 | 18 Şub 2026 |
35İzleyin | CVE-2017-1000238İstismar yok | InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the winvoiceplane · invoiceplane · CWE-434 | Yüksek8,8 | — | %1,1 | 16 Kas 2017 |
30İzleyin | CVE-2021-29024İstismar yok | In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download.invoiceplane · invoiceplane · CWE-552 | Yüksek7,5 | — | %1,6 | 17 May 2021 |
30İzleyin | CVE-2026-24746İstismar yok | InvoicePlane has a Stored Cross-Site Scripting (XSS) issueinvoiceplane · invoiceplane · CWE-79 | Yüksek7,5 | — | %0,3 | 18 Şub 2026 |
30İzleyin | CVE-2026-24744İstismar yok | InvoicePlane has a Stored Cross-Site Scripting (XSS) issueinvoiceplane · invoiceplane · CWE-79 | Yüksek7,5 | — | %0,2 | 18 Şub 2026 |
30İzleyin | CVE-2026-24745İstismar yok | InvoicePlane has a Stored Cross-Site Scripting (XSS) issueinvoiceplane · invoiceplane · CWE-79 | Yüksek7,5 | — | %0,2 | 18 Şub 2026 |
30İzleyin | CVE-2026-24743İstismar yok | InvoicePlane has a Stored Cross-Site Scripting (XSS) issueinvoiceplane · invoiceplane · CWE-79 | Yüksek7,5 | — | %0,2 | 18 Şub 2026 |
26İzleyin | CVE-2025-67082İstismar yok | An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generatiinvoiceplane · invoiceplane · CWE-89 | Orta6,5 | — | %0,3 | 15 Oca 2026 |
25İzleyin | CVE-2024-12667İstismar yok | InvoicePlane view session expirationinvoiceplane · invoiceplane · CWE-613 | Orta6,3 | — | %0,5 | 16 Ara 2024 |
24İzleyin | CVE-2017-18217İstismar yok | An issue was discovered in InvoicePlane before 1.5.5.invoiceplane · invoiceplane · CWE-79 | Orta6,1 | — | %1,3 | 5 Mar 2018 |
24İzleyin | CVE-2017-1000508İstismar yok | Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in executioninvoiceplane · invoiceplane · CWE-79 | Orta6,1 | — | %1,0 | 9 Şub 2018 |
24İzleyin | CVE-2018-12255İstismar yok | An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field.invoiceplane · invoiceplane · CWE-79 | Orta6,1 | — | %0,7 | 3 Tem 2018 |
24İzleyin | CVE-2023-23011İstismar yok | Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.invoiceplane · invoiceplane · CWE-79 | Orta6,1 | — | %0,5 | 7 Şub 2023 |
21İzleyin | CVE-2021-29023İstismar yok | InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predicinvoiceplane · invoiceplane · CWE-307 | Orta5,3 | — | %1,2 | 17 May 2021 |
21İzleyin | CVE-2021-29022İstismar yok | In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.invoiceplane · invoiceplane · CWE-434 | Orta5,3 | — | %1,1 | 10 May 2021 |
21İzleyin | CVE-2025-67083İstismar yok | Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server.invoiceplane · invoiceplane · CWE-22 | Orta5,3 | — | %0,7 | 15 Oca 2026 |
21İzleyin | CVE-2019-7223İstismar yok | InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Createinvoiceplane · invoiceplane · CWE-79 | Orta5,4 | — | %0,7 | 21 Mar 2019 |
21İzleyin | CVE-2024-12478İstismar yok | InvoicePlane 1 upload_file unrestricted uploadinvoiceplane · invoiceplane · CWE-284 | Orta5,3 | — | %0,6 | 16 Ara 2024 |
21İzleyin | CVE-2024-12362İstismar yok | InvoicePlane invoices.php download path traversalinvoiceplane · invoiceplane · CWE-22 | Orta5,3 | — | %0,6 | 16 Ara 2024 |
21İzleyin | CVE-2017-1000239İstismar yok | InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious cinvoiceplane · invoiceplane · CWE-79 | Orta5,4 | — | %0,5 | 16 Kas 2017 |
21İzleyin | CVE-2026-26270İstismar yok | InvoicePlane has Stored Cross-Site Scripting Issue in Identifier Formattinginvoiceplane · invoiceplane · CWE-79 | Orta5,4 | — | %0,2 | 18 Şub 2026 |
19İzleyin | CVE-2026-25594Kavram kanıtı | InvoicePlane has Stored XSS via Family Name in Product Forminvoiceplane · invoiceplane · CWE-79 | Orta4,8 | — | %0,3 | 18 Şub 2026 |
- CVE-2024-5697539İzleyin
InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file
KritikCVSS 9,8İstismar yokEPSS %1invoiceplane · invoiceplane28 Mar 2025
- CVE-2025-6708439İzleyin
File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which
KritikCVSS 9,9İstismar yokEPSS %0invoiceplane · invoiceplane15 Oca 2026
- CVE-2026-2349138İzleyin
InvoicePlane has Unauthenticated Path Traversal in Guest Controller
KritikCVSS 9,3Kavram kanıtıEPSS %4invoiceplane · invoiceplane18 Şub 2026
- CVE-2026-2554836İzleyin
InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoning
KritikCVSS 9,1Kavram kanıtıEPSS %1invoiceplane · invoiceplane18 Şub 2026
- CVE-2017-100023835İzleyin
InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the w
YüksekCVSS 8,8İstismar yokEPSS %1invoiceplane · invoiceplane16 Kas 2017
- CVE-2021-2902430İzleyin
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download.
YüksekCVSS 7,5İstismar yokEPSS %2invoiceplane · invoiceplane17 May 2021
- CVE-2026-2474630İzleyin
InvoicePlane has a Stored Cross-Site Scripting (XSS) issue
YüksekCVSS 7,5İstismar yokEPSS %0invoiceplane · invoiceplane18 Şub 2026
- CVE-2026-2474430İzleyin
InvoicePlane has a Stored Cross-Site Scripting (XSS) issue
YüksekCVSS 7,5İstismar yokEPSS %0invoiceplane · invoiceplane18 Şub 2026
- CVE-2026-2474530İzleyin
InvoicePlane has a Stored Cross-Site Scripting (XSS) issue
YüksekCVSS 7,5İstismar yokEPSS %0invoiceplane · invoiceplane18 Şub 2026
- CVE-2026-2474330İzleyin
InvoicePlane has a Stored Cross-Site Scripting (XSS) issue
YüksekCVSS 7,5İstismar yokEPSS %0invoiceplane · invoiceplane18 Şub 2026
- CVE-2025-6708226İzleyin
An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generati
OrtaCVSS 6,5İstismar yokEPSS %0invoiceplane · invoiceplane15 Oca 2026
- CVE-2024-1266725İzleyin
InvoicePlane view session expiration
OrtaCVSS 6,3İstismar yokEPSS %1invoiceplane · invoiceplane16 Ara 2024
- CVE-2017-1821724İzleyin
An issue was discovered in InvoicePlane before 1.5.5.
OrtaCVSS 6,1İstismar yokEPSS %1invoiceplane · invoiceplane5 Mar 2018
- CVE-2017-100050824İzleyin
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution
OrtaCVSS 6,1İstismar yokEPSS %1invoiceplane · invoiceplane9 Şub 2018
- CVE-2018-1225524İzleyin
An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field.
OrtaCVSS 6,1İstismar yokEPSS %1invoiceplane · invoiceplane3 Tem 2018
- CVE-2023-2301124İzleyin
Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.
OrtaCVSS 6,1İstismar yokEPSS %1invoiceplane · invoiceplane7 Şub 2023
- CVE-2021-2902321İzleyin
InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predic
OrtaCVSS 5,3İstismar yokEPSS %1invoiceplane · invoiceplane17 May 2021
- CVE-2021-2902221İzleyin
In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.
OrtaCVSS 5,3İstismar yokEPSS %1invoiceplane · invoiceplane10 May 2021
- CVE-2025-6708321İzleyin
Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server.
OrtaCVSS 5,3İstismar yokEPSS %1invoiceplane · invoiceplane15 Oca 2026
- CVE-2019-722321İzleyin
InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create
OrtaCVSS 5,4İstismar yokEPSS %1invoiceplane · invoiceplane21 Mar 2019
- CVE-2024-1247821İzleyin
InvoicePlane 1 upload_file unrestricted upload
OrtaCVSS 5,3İstismar yokEPSS %1invoiceplane · invoiceplane16 Ara 2024
- CVE-2024-1236221İzleyin
InvoicePlane invoices.php download path traversal
OrtaCVSS 5,3İstismar yokEPSS %1invoiceplane · invoiceplane16 Ara 2024
- CVE-2017-100023921İzleyin
InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious c
OrtaCVSS 5,4İstismar yokEPSS %0invoiceplane · invoiceplane16 Kas 2017
- CVE-2026-2627021İzleyin
InvoicePlane has Stored Cross-Site Scripting Issue in Identifier Formatting
OrtaCVSS 5,4İstismar yokEPSS %0invoiceplane · invoiceplane18 Şub 2026
- CVE-2026-2559419İzleyin
InvoicePlane has Stored XSS via Family Name in Product Form
OrtaCVSS 4,8Kavram kanıtıEPSS %0invoiceplane · invoiceplane18 Şub 2026