Vulnerabilities
Summary — last 7 days
New vulnerabilities2,783▲ 27 vs. last week
Critical / high1,477▲ 294 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)68▼ 441 vs. last week
498 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.2) | 0.28% | — | PDF Invoices Packing Slips FOR WoocommerceAI | 10/1/2026 | 10/1/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields in all versions up to, and including, 5.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Deferred | Medium (5.3) | 0.23% | — | Sprout InvoicesAI | 9/30/2026 | 9/30/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions. | |
| Deferred | Medium (6.3) | 0.51% | — | Mbailey VoicemodeAI | 9/29/2026 | 9/30/2026 | mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the "voicemode config set" CLI) writes a caller-supplied value into ~/.voicemode/voicemode.env without shell-safe escaping. | |
| Deferred | High (7) | 0.23% | — | InvoiceplaneAI | 9/28/2026 | 9/30/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) can rewrite the Primary Administrator's user_type to 2 (Guest /… | |
| Deferred | High (8.7) | 0.28% | — | InvoiceplaneAI | 9/28/2026 | 9/30/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, an authorization guard to Users::change_password(), was added to address a previous authorization flaw that allowed a secondary administrator (user_type=1, user_id != 1) to directly change the password… | |
| Deferred | High (8.7) | 0.25% | — | Openclaw Voice CallAI | 9/26/2026 | 9/29/2026 | openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose the agent's normal tool authority to a remote caller. A caller who is… | |
| Deferred | High (7.5) | 0.30% | — | InvoiceplaneAI | 9/25/2026 | 9/28/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane fails to revoke administrative privileges after a role downgrade because Admin_Controller trusts the user_type snapshot stored in an existing session instead of revalidating… | |
| Deferred | Medium (4.8) | 0.22% | — | InvoiceplaneAI | 9/25/2026 | 9/28/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-beta-1, InvoicePlane stores client_email values without enforcing email syntax and renders them unescaped inside double-quoted value attributes in the invoice mailer form and quote mailer form. An… | |
| Deferred | Medium (4.8) | 0.25% | — | InvoiceplaneAI | 9/25/2026 | 9/28/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's User_Controller compares the session user_type value with the required role by using PHP's loose inequality operator. Under a non-standard session backend that returns unexpected scalar… | |
| Deferred | Medium (6.5) | 0.26% | — | InvoiceplaneAI | 9/25/2026 | 9/28/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Users::change_password() method accepts a user_id from the URL and updates that account's password without an object-level authorization check. An authenticated secondary administrator can… | |
| Deferred | Medium (5.3) | 0.24% | — | InvoiceplaneAI | 9/25/2026 | 9/29/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from the URL path directly to the application log without neutralizing CRLF characters. An unauthenticated requester can place forged log… | |
| Deferred | Medium (6.5) | 0.17% | — | InvoiceplaneAI | 9/25/2026 | 9/28/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane omits ensure_valid_post_request() from delete methods including Payments::delete(), Recurring::delete(), and User_clients::delete(). Although the routes require POST, they do not validate… | |
| Deferred | Medium (6.5) | 0.17% | — | InvoiceplaneAI | 9/25/2026 | 9/28/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Recurring::stop() as a state-changing GET route without CSRF token validation. When an authenticated administrator loads attacker-controlled content that requests… | |
| Deferred | Medium (6) | 0.23% | — | InvoiceplaneAI | 9/25/2026 | 9/28/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores an administrator-controlled custom_field_table value without validating it against the allowed custom-field table names. Mdl_custom_fields::used() later concatenates that stored value… | |
| Deferred | High (7.5) | 0.46% | — | InvoiceplaneAI | 9/25/2026 | 9/28/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Invoices::generate_xml() method appends a database-derived xml_id to the XMLconfigs helper directory and includes the resulting PHP path without validating the identifier. A low-privileged… | |
| Deferred | High (7.5) | 0.33% | — | InvoiceplaneAI | 9/25/2026 | 9/28/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without requiring POST and validating a CSRF token. When an authenticated administrator loads… | |
| Deferred | Medium (4.9) | 0.28% | — | InvoiceplaneAI | 9/25/2026 | 9/29/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores and serves uploaded image attachments without stripping EXIF metadata. When an administrator uploads an image through invoice attachments, quote attachments, or another attachment… | |
| Deferred | Critical (9.1) | 0.45% | — | InvoiceplaneAI | 9/25/2026 | 9/28/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an administrator-controlled file-write capability. A malicious PHP file placed in the… | |
| Deferred | High (7.2) | 0.40% | — | InvoiceplaneAI | 9/25/2026 | 9/29/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for ip_tax_rates in Settings::index() without strict integer validation. A crafted… | |
| Deferred | High (7.3) | 0.39% | — | Opentext Vendor Invoice Management FOR SAP SolutionsAI | 9/24/2026 | 9/24/2026 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and… | |
| Awaiting Analysis | High (8.7) | 0.30% | — | InvoiceshelfAI | 9/23/2026 | 9/23/2026 | InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.4.1, in InvoiceShelf's multi-company installations, any user who is an Owner of one company can read and overwrite any user account in any other company on the same… | |
| Deferred | Medium (5.3) | 0.31% | — | Easy InvoiceAI | 9/17/2026 | 9/17/2026 | Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions. | |
| Deferred | Medium (4.3) | 0.25% | — | Sprout InvoicesAI | 9/12/2026 | 9/14/2026 | The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records belonging to other users. | |
| Deferred | Medium (6.5) | 0.26% | — | WOO PDF Invoice BuilderAI | 9/11/2026 | 9/11/2026 | The Woo PDF Invoice Builder plugin (also distributed as "PDF Builder for WooCommerce") for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8. This is due to the InspectOrder() AJAX handler (woocommerce-pdf-invoice-ajax.php:513), registered on… | |
| Analyzed | Medium (4.8) | 0.08% | — | Samsung Visual Voicemail | 9/9/2026 | 9/23/2026 | Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission. |