Matcha Invoice
Vendor:
First CVE: Apr 8, 2026 · Active for under a year
2
Total CVEs
More Total CVEs than 53% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 72% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Matcha Invoice over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 8, 2026
3 months ago
Most Recent CVE
Apr 8, 2026
110 days ago
CVE Severity & Scoring
Matcha Invoice2 CVEs
100%
All CVEs352,785 CVEs
45%
40%
11%
High
Attack Vector
Local0 (0.0%)
Network2 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (50.0%)
High1 (50.0%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24913HIGH SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user | Apr 8, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-33273HIGH Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an adminis | Apr 8, 2026 | 7.2 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (2 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (2 CVEs).
Media Mentions
Signals from CVEs in this product scope (2 CVEs).
Top CNAs Publishing CVEs For Matcha Invoice
Top CWEs
Versions
No cataloged versions.