PT-2026-48727 · Unknown · Solidinvoice

CVE-2026-46489

·

Published

2026-06-11

·

Updated

2026-06-12

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SolidInvoice versions prior to 2.3.17
Description The company logo upload feature lacks validation for uploaded file types. An authenticated administrator can upload an SVG file containing base64-encoded JavaScript. This script is injected unescaped into every page of the application, resulting in stored cross-site scripting (XSS), which is a vulnerability where malicious scripts are permanently stored on the target server and executed in the browsers of other authenticated users.
Recommendations Update to version 2.3.17.

Exploit

Fix

XSS

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46489
GHSA-MQWM-R4G8-WF4W

Affected Products

Solidinvoice