PT-2026-28521 · Unknown+1 · Invoice Ninja+1

Morimori-Dev

·

Publicado

2026-03-26

·

Atualizado

2026-03-26

·

CVE-2026-33742

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Invoice Ninja versions 5.13.0 through 5.13.3
Description Invoice Ninja, an invoice, quote, project, and time-tracking application built with Laravel, has an issue where the product notes fields in versions 5.13.0 through 5.13.3 allow raw HTML through Markdown rendering, potentially leading to stored cross-site scripting (XSS). The Markdown parser's output was not properly sanitized using the purify::clean() function before being included in invoice templates. This could allow an attacker to inject malicious code into the system.
Recommendations Update to version 5.13.4 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33742
GHSA-XPH7-9749-56MH

Produtos afetados

Invoice Ninja
Laravel