PT-2026-3028 · Unknown · Invoiceplane

CVE-2025-67084

·

Published

2026-01-15

·

Updated

2026-01-22

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions InvoicePlane versions through 1.6.3
Description A file upload issue exists in InvoicePlane that allows authenticated attackers to upload arbitrary PHP files into attachments. These uploaded files can then be executed remotely, potentially leading to Remote Code Execution (RCE). The affected API endpoint is the file upload functionality. The vulnerable parameter is the file itself, allowing the upload of malicious PHP scripts.
Recommendations Update InvoicePlane to a version later than 1.6.3.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67084

Affected Products

Invoiceplane