PT-2026-98883 · Unknown · Invoiceplane

CVE-2026-85274

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions InvoicePlane versions prior to 1.7.2
Description InvoicePlane exposes the Recurring::stop() function as a state-changing GET route that lacks Cross-Site Request Forgery (CSRF) token validation. CSRF is a type of attack that tricks a victim into submitting a malicious request. An authenticated administrator loading attacker-controlled content that requests the '/invoices/recurring/stop/{id}' endpoint can trigger the stopping of a selected recurring invoice. Attackers may target multiple identifiers to interrupt recurring billing, potentially leading to financial loss.
Recommendations Update to version 1.7.2.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85274
GHSA-QF9Q-2HXM-4WH9

Affected Products

Invoiceplane