Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

fossbilling — Vulnerabilities & Security Advisories 38

Browse all 38 CVE security advisories affecting fossbilling. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FOSSBilling serves as an open-source billing and invoicing platform for web hosting and SaaS businesses. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting (XSS), privilege escalation flaws, and insecure direct object references. The platform's 11 recorded CVEs highlight recurring issues in input validation, access control, and session management. While no major public security incidents have been documented, the consistent pattern of vulnerabilities suggests developers should implement strict input sanitization, enforce proper authentication mechanisms, and regularly update the system to mitigate potential exploitation risks.

Top products by fossbilling: FOSSBilling fossbilling/fossbilling
CVE IDTitleCVSSSeverityPublished
CVE-2026-53648 FOSSBilling: Downloadable product files can be overwritten through filename collisions — FOSSBillingCWE-73--2026-07-06
CVE-2026-53647 FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint — FOSSBillingCWE-200--2026-07-06
CVE-2026-53646 FOSSBilling: Client password reset token reuse allows persistent account takeover — FOSSBillingCWE-640--2026-07-06
CVE-2026-53645 FOSSBilling's missing self-edit prevention in staff permission management allows persistent privilege escalation — FOSSBillingCWE-269--2026-07-06
CVE-2026-53644 FOSSBilling's missing order-state validation allows clients to read and reset API key secrets for non-active orders — FOSSBillingCWE-639--2026-07-06
CVE-2026-53643 FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints — FOSSBillingCWE-200--2026-07-06
CVE-2026-53642 FOSSBilling: Unverified clients can access client-area pages when email confirmation is required — FOSSBillingCWE-863--2026-07-06
CVE-2026-53641 FOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literal — FOSSBillingCWE-79--2026-07-06
CVE-2026-53640 FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data — FOSSBillingCWE-200--2026-07-06
CVE-2026-43928 FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpayment — FOSSBillingCWE-754--2026-07-06
CVE-2026-43927 FOSSBilling has race condition in cart checkout that bypasses promo code usage limits — FOSSBillingCWE-367--2026-07-06
CVE-2026-43925 FOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code use — FOSSBillingCWE-915--2026-07-06
CVE-2026-43921 FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config serialization — FOSSBillingCWE-94--2026-07-06
CVE-2026-43918 Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flows — FOSSBillingCWE-613--2026-07-06
CVE-2026-42331 FOSSBilling missing authorization in guest Invoice API endpoints — FOSSBillingCWE-306--2026-07-06
CVE-2026-33734 FOSSBilling has improper SQL neutralization in `Massmailer` recipient filters — FOSSBillingCWE-89--2026-07-06
CVE-2026-42341 FOSSBilling has an unauthenticated payment bypass via IPN callback forgery — FOSSBillingCWE-306--2026-07-06
CVE-2026-43920 FOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance execution — FOSSBillingCWE-306--2026-06-25
CVE-2026-33543 FOSSBilling: Authentication bypass allows unauthenticated administrator creation — FOSSBillingCWE-288--2026-06-24
CVE-2026-27708 FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access — FOSSBillingCWE-284--2026-06-24
CVE-2026-23513 FOSSBilling: Broken Authorization in Client Transaction and Order Listings — FOSSBillingCWE-863--2026-06-23
CVE-2025-64105 FOSSBilling: IDOR Vulnerability in Support Ticket Creation — FOSSBillingCWE-639--2026-06-23
CVE-2026-27604 FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin Functions — FOSSBillingCWE-200--2026-06-23
CVE-2026-28496 FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE — FOSSBillingCWE-1336--2026-06-23
CVE-2026-43926 FOSSBilling's password reset confirmation endpoint lacks rate limiting — FOSSBillingCWE-204--2026-06-04
CVE-2026-43924 FOSSBilling has an open redirect via administrator-configured redirect targets — FOSSBillingCWE-601--2026-06-03
CVE-2026-40495 FOSSBilling version exposed via asset cache buster — FOSSBillingCWE-200--2026-06-03
CVE-2023-4005 Insufficient Session Expiration in fossbilling/fossbilling — fossbilling/fossbillingCWE-613 8.8 -2023-07-31
CVE-2023-3521 Cross-site Scripting (XSS) - Reflected in fossbilling/fossbilling — fossbilling/fossbillingCWE-79 5.4 -2023-07-06
CVE-2023-3493 Improper Neutralization of Formula Elements in a CSV File in fossbilling/fossbilling — fossbilling/fossbillingCWE-1236 8.0 -2023-06-30

This page lists every published CVE security advisory associated with fossbilling. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.