PT-2026-3028 · Unknown · Invoiceplane

Published

2026-01-15

·

Updated

2026-01-22

·

CVE-2025-67084

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions InvoicePlane versions through 1.6.3
Description A file upload issue exists in InvoicePlane that allows authenticated attackers to upload arbitrary PHP files into attachments. These uploaded files can then be executed remotely, potentially leading to Remote Code Execution (RCE). The affected API endpoint is the file upload functionality. The vulnerable parameter is the file itself, allowing the upload of malicious PHP scripts.
Recommendations Update InvoicePlane to a version later than 1.6.3.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-67084

Affected Products

Invoiceplane