SolidInvoice is a modestly represented web-based invoicing and financial management application whose vulnerability profile centers on input-handling and code-generation weaknesses, particularly cross-site scripting and code injection flaws typical of server-side web applications. These weakness classes reflect the application's role in processing and rendering user-supplied financial data and templates, making input validation and output encoding durable concerns for defenders deploying this software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Solidinvoice over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9171MEDIUM A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component Clients Module. Performing manipu | Aug 19, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-9170MEDIUM A vulnerability was identified in SolidInvoice up to 2.4.0. The affected element is an unknown function of the file /tax/rates of the component Tax Rates Module. Such manipulation | Aug 19, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-9168MEDIUM A vulnerability was found in SolidInvoice up to 2.4.0. This issue affects some unknown processing of the file /invoice of the component Invoice Creation Module. The manipulation of | Aug 19, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-9167MEDIUM A vulnerability has been found in SolidInvoice up to 2.4.0. This vulnerability affects unknown code of the file /invoice/recurring of the component Recurring Invoice Module. The ma | Aug 19, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-55580MEDIUM SolidInvoice version 2.3.7 is vulnerable to a stored cross-site scripting (XSS) issue in the Clients module. An authenticated attacker can inject JavaScript that executes in other | Aug 29, 2025 | 5.4 | 19 | NO | NO |
CVE-2025-55579MEDIUM SolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. The vulnerability is fixed in version 2.3.8. | Aug 29, 2025 | 5.4 | 19 | NO | NO |
CVE-2025-9169MEDIUM A vulnerability was determined in SolidInvoice up to 2.4.0. Impacted is an unknown function of the file /quotes of the component Quote Module. This manipulation of the argument Nam | Aug 19, 2025 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Solidinvoice.
Media articles that mention a CVE ID that affects a product developed by Solidinvoice — matched by CVE ID, not by vendor name.