PT-2026-20552 · Invoiceplane · Invoiceplane

Lagathos

·

Published

2026-02-18

·

Updated

2026-02-24

·

CVE-2026-25596

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions InvoicePlane version 1.7.0 InvoicePlane versions prior to 1.7.1
Description A Stored Cross-Site Scripting (XSS) issue exists in InvoicePlane. An authenticated administrator can inject malicious JavaScript through the Product Unit Name fields. This malicious code executes when any administrator views an invoice containing a product with the injected code. The vulnerable parameter is the Product Unit Name.
Recommendations Update to version 1.7.1 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-25596
GHSA-3WJQ-822Q-98F4

Affected Products

Invoiceplane