PT-2026-31083 · Icz · Matcha Invoice

Published

2026-04-08

·

Updated

2026-04-08

·

CVE-2026-24913

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-24913

Affected Products

Matcha Invoice