PT-2026-28521 · Unknown+1 · Invoice Ninja+1
Morimori-Dev
·
Published
2026-03-26
·
Updated
2026-03-26
·
CVE-2026-33742
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Invoice Ninja versions 5.13.0 through 5.13.3
Description
Invoice Ninja, an invoice, quote, project, and time-tracking application built with Laravel, has an issue where the product notes fields in versions 5.13.0 through 5.13.3 allow raw HTML through Markdown rendering, potentially leading to stored cross-site scripting (XSS). The Markdown parser's output was not properly sanitized using the
purify::clean() function before being included in invoice templates. This could allow an attacker to inject malicious code into the system.Recommendations
Update to version 5.13.4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Invoice Ninja
Laravel