CVE-2026-24744 describes a Stored Cross-Site Scripting (XSS) vulnerability in InvoicePlane version 1.7.0, specifically within the Edit Invoices function due to improper validation of the invoice_number parameter. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating that while it requires administrator privileges for exploitation, it can lead to significant impacts such as unauthorized data modification, persistent backdoors, and compromise of application integrity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE. The issue is patched in InvoicePlane version 1.7.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.0CPE matchmatch criteria | cpe:2.3:a:invoiceplane:invoiceplane:1.7.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.