PT-2026-20552 · Invoiceplane · Invoiceplane

·

CVE-2026-25596

·

Published

2026-02-18

·

Updated

2026-02-24

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions InvoicePlane version 1.7.0 InvoicePlane versions prior to 1.7.1
Description A Stored Cross-Site Scripting (XSS) issue exists in InvoicePlane. An authenticated administrator can inject malicious JavaScript through the Product Unit Name fields. This malicious code executes when any administrator views an invoice containing a product with the injected code. The vulnerable parameter is the Product Unit Name.
Recommendations Update to version 1.7.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25596
GHSA-3WJQ-822Q-98F4

Affected Products

Invoiceplane