PT-2026-29343 · Unknown+1 · Invoiceshelf+1

Lagongit

·

Published

2026-03-31

·

Updated

2026-04-01

·

CVE-2026-34367

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions InvoiceShelf versions prior to 2.2.0
Description InvoiceShelf is a web and mobile application for tracking expenses, payments, and creating invoices and estimates. A Server-Side Request Forgery (SSRF) vulnerability exists in the Invoice PDF generation module in versions prior to 2.2.0. User-supplied HTML within the invoice Notes field is passed without sanitization to the Dompdf rendering library, allowing it to fetch remote resources referenced in the HTML markup. This can be triggered through the PDF preview and email delivery endpoints.
Recommendations Update to version 2.2.0 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-34367
GHSA-Q9WX-GGWQ-MCGH

Affected Products

Dompdf
Invoiceshelf