Unknown · Invoice Ninja · CVE-2026-29925
**Name of the Vulnerable Software and Affected Versions**
Invoice Ninja versions 5.12.46 and 5.12.48
**Description**
Invoice Ninja versions 5.12.46 and 5.12.48 are susceptible to a Server-Side Request Forgery (SSRF) condition. This issue is located in the `CheckDatabaseRequest.php` file. SSRF occurs when an application makes requests to unintended locations, potentially exposing sensitive data or allowing unauthorized actions.
**Recommendations**
Update Invoice Ninja to a version newer than 5.12.48.
Update Invoice Ninja to a version newer than 5.12.46.