Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

FOSSBilling — Vulnerabilities & Security Advisories 38

Browse all 38 CVE security advisories affecting FOSSBilling. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FOSSBilling serves as an open-source billing and invoicing platform for web hosting and SaaS businesses. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting (XSS), privilege escalation flaws, and insecure direct object references. The platform's 11 recorded CVEs highlight recurring issues in input validation, access control, and session management. While no major public security incidents have been documented, the consistent pattern of vulnerabilities suggests developers should implement strict input sanitization, enforce proper authentication mechanisms, and regularly update the system to mitigate potential exploitation risks.

Top products by FOSSBilling: FOSSBilling fossbilling/fossbilling
MediumCVE-2020-53472026-07-07
Unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint · Advisory · FOSSBilling/FOSS
High2026-07-07
Missing self-edit prevention in staff permission management allows persistent privilege escalation · Advisory · FOSSBill
Critical2026-07-07
Client password reset token reuse allows persistent account takeover · Advisory · FOSSBilling/FOSSBilling · GitHub
High2026-07-07
Multiple authorization flaws in admin API endpoints · Advisory · FOSSBilling/FOSSBilling · GitHub
Medium2026-07-07
Unverified clients can access client-area pages when email confirmation is required · Advisory · FOSSBilling/FOSSBilling
HighGHSA-vulnerability2026-07-07
Missing order-state validation allows clients to read and reset API key secrets for non-active orders · Advisory · FOSSB
High2026-07-07
Missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data · Adviso
Medium2026-07-07
Race condition in cart checkout bypasses promo code usage limits · Advisory · FOSSBilling/FOSSBilling · GitHub
High2026-07-07
Unauthenticated payment bypass via IPN callback forgery · Advisory · FOSSBilling/FOSSBilling · GitHub
HighCVE-2026-023312026-07-07
Missing authorization in guest Invoice API endpoints · Advisory · FOSSBilling/FOSSBilling · GitHub
MediumGHSA-f7m-j559-28992026-07-07
Improper SQL neutralization in Massmailer recipient filters · Advisory · FOSSBilling/FOSSBilling · GitHub
High2026-06-27
Authentication bypass allows unauthenticated administrator creation · Advisory · FOSSBilling/FOSSBilling · GitHub
CriticalGHSA-78v5-cdqw-82792026-06-27
Server-side template injection in Twig template rendering enables information disclosure and RCE · Advisory · FOSSBillin
Critical2026-06-27
Improper API role validation (system) enables unauthenticated access to privileged admin functions · Advisory · FOSSBill
High2026-06-27
IDOR in Servicecustom client API allows cross-client data access · Advisory · FOSSBilling/FOSSBilling · GitHub
MediumCVE-2024-439202026-06-27
Unauthenticated update patcher endpoint allows remote maintenance execution · Advisory · FOSSBilling/FOSSBilling · GitHu
HighCVE-2026-25132026-06-27
Broken authorization in client transaction and order listings · Advisory · FOSSBilling/FOSSBilling · GitHub
MediumCVE-2025-641052026-06-27
Support ticket order relation IDOR allows cross‑client order references · Advisory · FOSSBilling/FOSSBilling · GitHub
High2026-06-13
Release 0.8.0 · FOSSBilling/FOSSBilling · GitHub
Medium2026-06-13
Password reset confirmation endpoint lacks rate limiting · Advisory · FOSSBilling/FOSSBilling · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with FOSSBilling. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.