PT-2026-20551 · Unknown · Invoiceplane

Lagathos

·

Publicado

2026-02-18

·

Atualizado

2026-02-24

·

CVE-2026-25595

CVSS v3.1

4.8

Média

VetorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions InvoicePlane versions prior to 1.7.1
Description A Stored Cross-Site Scripting (XSS) issue exists in InvoicePlane. An authenticated administrator can inject malicious JavaScript through the Invoice Number field. This injected script executes when any administrator views the affected invoice or accesses the dashboard.
Recommendations Update to version 1.7.1 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25595
GHSA-XXVR-2564-6JG6

Produtos afetados

Invoiceplane