Browse all 3 CVE security advisories affecting Invoice Ninja. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Invoice Ninja is an open-source invoicing and billing platform designed for freelancers and small businesses to manage invoices, expenses, and payments. Historically, it has been susceptible to multiple critical vulnerabilities including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, primarily stemming from improper input validation and access control issues. The platform has three documented CVEs, with notable security concerns including insecure default configurations and insufficient session management. While no major public security incidents have been widely reported, the recurring nature of these vulnerabilities highlights the importance of timely updates and hardening for production deployments.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-10009 | Authenticated admin RCE in Invoice Ninja — Invoice Ninja 5CWE-434 | 7.2AI | HighAI | 2025-09-22 |
This page lists every published CVE security advisory associated with Invoice Ninja. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.