Invoiceninja
Invoiceninja Invoice Ninja: vulnerabilidades y CVE
Invoiceninja Invoice Ninja tiene 14 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses7
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-71626 | Alta (7.5) | 0.53% | — | 4 sept 2026 | An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components |
| CVE-2026-83744 | Baja (2.1) | 0.35% | — | 1 sept 2026 | A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability affects the function Purify::isHostSafe of the file app/Services/Pdf/Purify.php of the component invoices… |
| CVE-2026-83743 | Baja (2.1) | 0.38% | — | 1 sept 2026 | A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipulation of the… |
| CVE-2026-58450 | Media (5.3) | 0.29% | — | 30 jun 2026 | Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthenticated attackers to redirect authenticated victims to attacker-controlled external URLs by injecting… |
| CVE-2026-29925 | Alta (7.7) | 0.37% | — | 30 mar 2026 | Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php. |
| CVE-2026-33742 | Media (5.4) | 0.25% | — | 26 mar 2026 | Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Product notes fields in Invoice Ninja v5.13.0 allow raw HTML via Markdown rendering, enabling stored XSS. The… |
| CVE-2026-33628 | Media (5.4) | 0.30% | — | 26 mar 2026 | Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item descriptions in Invoice Ninja v5.13.0 bypass the XSS denylist filter, allowing stored XSS payloads… |
| CVE-2025-10009 | Alta (8.6) | 0.50% | — | 22 sept 2025 | Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with admin credentials to execute arbitrary code on the server via uploaded .php files. |
| CVE-2025-8700 | Media (4.8) | 0.14% | — | 26 ago 2025 | Invoice Ninja's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", allows local attackers with unprivileged access (e.g. via a malicious application) to attach a… |
| CVE-2025-0474 | Alta (7.7) | 0.40% | — | 14 ene 2025 | Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56… |
| CVE-2024-55555 | Alta (8.8) | 6.7% | — | 7 ene 2025 | Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default… |
| CVE-2021-3977 | Media (5.4) | 0.59% | — | 24 dic 2021 | invoiceninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-33898 | Alta (8.1) | 1.8% | — | 6 jun 2021 | In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to deserialize arbitrary PHP classes. In certain contexts, this can… |
| CVE-2017-1000466 | Media (5.4) | 0.79% | — | 3 ene 2018 | Invoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page, which can result in disruption of service and execution of javascript code. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.