CVE-2026-24743 is a stored Cross-Site Scripting (XSS) vulnerability in InvoicePlane version 1.7.0, specifically within the "Upload Invoice Logo" function, which improperly handles SVG file uploads. This high-severity vulnerability (CVSS 7.5) requires administrator privileges but can lead to unauthorized data modification, persistent backdoors, and application integrity compromise. While no active exploitation, public exploit code, or significant community discussion has been observed, organizations using affected versions should upgrade to 1.7.1 immediately to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.0CPE matchmatch criteria | cpe:2.3:a:invoiceplane:invoiceplane:1.7.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.