« Volver al listado

Invoiceninja

Invoiceninja Invoice Ninja: vulnerabilidades y CVE

Invoiceninja Invoice Ninja tiene 14 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE14
Últimos 12 meses7
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-71626Alta (7.5)0.53%—4 sept 2026
An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components
CVE-2026-83744Baja (2.1)0.35%—1 sept 2026
A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability affects the function Purify::isHostSafe of the file app/Services/Pdf/Purify.php of the component invoices…
CVE-2026-83743Baja (2.1)0.38%—1 sept 2026
A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipulation of the…
CVE-2026-58450Media (5.3)0.29%—30 jun 2026
Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthenticated attackers to redirect authenticated victims to attacker-controlled external URLs by injecting…
CVE-2026-29925Alta (7.7)0.37%—30 mar 2026
Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.
CVE-2026-33742Media (5.4)0.25%—26 mar 2026
Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Product notes fields in Invoice Ninja v5.13.0 allow raw HTML via Markdown rendering, enabling stored XSS. The…
CVE-2026-33628Media (5.4)0.30%—26 mar 2026
Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item descriptions in Invoice Ninja v5.13.0 bypass the XSS denylist filter, allowing stored XSS payloads…
CVE-2025-10009Alta (8.6)0.50%—22 sept 2025
Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with admin credentials to execute arbitrary code on the server via uploaded .php files.
CVE-2025-8700Media (4.8)0.14%—26 ago 2025
Invoice Ninja's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", allows local attackers with unprivileged access (e.g. via a malicious application) to attach a…
CVE-2025-0474Alta (7.7)0.40%—14 ene 2025
Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56…
CVE-2024-55555Alta (8.8)6.7%—7 ene 2025
Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default…
CVE-2021-3977Media (5.4)0.59%—24 dic 2021
invoiceninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-33898Alta (8.1)1.8%—6 jun 2021
In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to deserialize arbitrary PHP classes. In certain contexts, this can…
CVE-2017-1000466Media (5.4)0.79%—3 ene 2018
Invoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page, which can result in disruption of service and execution of javascript code.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services4
  2. T1090 Proxy2
  3. T1005 Data from Local System1
  4. T1059 Command and Scripting Interpreter1
  5. T1190 Exploit Public-Facing Application1
  6. T1505.003 Web Shell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Invoiceninja