Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| InvoicePlane | InvoicePlane | <= 1.7.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-25548 | 9.1 CRITICAL | InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisonin |
| CVE-2026-24746 | 5.7 MEDIUM | InvoicePlane has a Stored Cross-Site Scripting (XSS) issue |
| CVE-2026-24744 | 5.7 MEDIUM | InvoicePlane has a Stored Cross-Site Scripting (XSS) issue |
| CVE-2026-24745 | 5.7 MEDIUM | InvoicePlane has a Stored Cross-Site Scripting (XSS) issue |
| CVE-2026-24743 | 5.7 MEDIUM | InvoicePlane has a Stored Cross-Site Scripting (XSS) issue |
| CVE-2026-26270 | 5.4 MEDIUM | InvoicePlane has Stored Cross-Site Scripting Issue in Identifier Formatting |
| CVE-2026-25594 | 4.8 MEDIUM | InvoicePlane has Stored XSS via Family Name in Product Form |
| CVE-2026-25596 | 4.8 MEDIUM | InvoicePlane has Stored XSS via Product Unit Name in Invoice Item List |
| CVE-2026-26281 | 4.4 MEDIUM | InvoicePlane has Stored Cross-Site Scripting (XSS) Issue in Sumex Invoice View |
| CVE-2026-23491 | InvoicePlane has Unauthenticated Path Traversal in Guest Controller |
No comments yet