PT-2026-29341 · Unknown+1 · Invoiceshelf+1

Lagongit

·

Published

2026-03-31

·

Updated

2026-04-01

·

CVE-2026-34365

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions InvoiceShelf versions prior to 2.2.0
Description InvoiceShelf is a web and mobile application used for expense tracking, payments, invoice creation, and estimates. A Server-Side Request Forgery (SSRF) exists in the Estimate PDF generation module in versions prior to 2.2.0. User-supplied HTML within the estimate Notes field is passed without sanitization to the Dompdf rendering library, allowing it to fetch remote resources referenced in the HTML markup. The vulnerability is exploitable through the PDF preview and customer view endpoints.
Recommendations Update to version 2.2.0 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34365
GHSA-PC5V-8XWC-V9XQ

Affected Products

Dompdf
Invoiceshelf