Invoiceplane is a self-hosted open-source invoicing and billing application that, despite a narrow product scope, occupies a position among more prominent vendors in the vulnerability landscape, likely reflecting its adoption across small and mid-sized business operations. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity. The exposure recurs consistently through a set of characteristic application-layer weaknesses: cross-site scripting in dynamic content generation, unrestricted file uploads, path traversal in directory access, authorization bypass through user-controlled keys, and improper disclosure of files and directories—each typical of web application frameworks where input validation, file handling, and access control are not uniformly hardened across the codebase. Defenders deploying this software should prioritize patching releases addressing these classes and restrict network exposure where feasible. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Invoiceplane over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67084CRITICAL File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading | Jan 15, 2026 | 9.9 | 34 | NO | NO |
CVE-2026-25548CRITICAL InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7. | Feb 18, 2026 | 9.1 | 33 | NO | NO |
CVE-2024-56975CRITICAL InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller. | Mar 28, 2025 | 9.8 | 26 | NO | NO |
CVE-2026-24745HIGH InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the upload Login Log | Feb 18, 2026 | 7.5 | 25 | NO | NO |
CVE-2017-1000238HIGH InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacker | Nov 17, 2017 | 8.8 | 25 | NO | NO |
CVE-2026-24744HIGH InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the Edit Invoices fu | Feb 18, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-24743HIGH InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the upload Invoice L | Feb 18, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-24746HIGH InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the Edit Quotes func | Feb 18, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-23491HIGH InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vulnerability exists in the `get_file` method of the `Guest` mo | Feb 18, 2026 | 7.5 | 24 | NO | NO |
CVE-2024-12478HIGH A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the function upload_file of the file /index.php/upload/upload_fi | Dec 16, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Invoiceplane.
Media articles that mention a CVE ID that affects a product developed by Invoiceplane — matched by CVE ID, not by vendor name.