Fossbilling is a self-hosted billing and client-management platform that occupies a focused niche in hosted infrastructure software, with concentrated exposure across its single core product. Vulnerabilities affecting the vendor skew toward serious outcomes and show a moderate tendency toward public exploit availability, while the recurring weakness classes—code injection, cross-site scripting, SQL injection, and CSV formula injection—reflect the input-handling and data-processing surface inherent to web-based administrative and reporting interfaces. Defenders running or considering this platform should prioritize security updates and input validation controls; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fossbilling over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-3490CRITICAL SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3. | Jun 30, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-4005CRITICAL Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5. | Jul 31, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-3521MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4. | Jul 6, 2023 | 6.1 | 28 | NO | YES |
CVE-2023-3491HIGH Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3. | Jun 30, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-3493HIGH Improper Neutralization of Formula Elements in a CSV File in GitHub repository fossbilling/fossbilling prior to 0.5.3. | Jun 30, 2023 | 8.0 | 23 | NO | NO |
CVE-2023-3230HIGH Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0. | Jun 14, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-3229MEDIUM Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0. | Jun 14, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-3393HIGH Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1. | Jun 23, 2023 | 7.2 | 21 | NO | NO |
CVE-2023-3568MEDIUM Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
| Jul 10, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-3394MEDIUM Session Fixation in GitHub repository fossbilling/fossbilling prior to 0.5.1. | Jun 23, 2023 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fossbilling.
Media articles that mention a CVE ID that affects a product developed by Fossbilling — matched by CVE ID, not by vendor name.