PT-2026-27631 · Unknown · Invoice Ninja

·

CVE-2026-33628

·

Published

2026-03-24

·

Updated

2026-08-05

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Invoice Ninja versions 5.13.0 through 5.13.3
Description Invoice Ninja is a source-available invoice, quote, project, and time-tracking application built with Laravel. The application contains a flaw where invoice line item descriptions bypass the XSS denylist filter, enabling stored Cross-Site Scripting (XSS) payloads to execute when invoices are rendered in the client portal or PDF preview. This occurs because the line item description field is not processed through the purify::clean() function before rendering. An authenticated user capable of creating invoices can inject malicious scripts that may lead to session hijacking, account takeover, or data exfiltration when viewed by other users or clients.
Recommendations Update Invoice Ninja to version 5.13.4.

Exploit

Fix

XSS

Incomplete List of Disallowed Inputs

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33628
GHSA-98WM-CXPW-847P

Affected Products

Invoice Ninja