CVE-2026-25595
Last modified
CVE-2026-25595 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Invoice Number field. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Invoice Number field. An authenticated administrator can inject malicious JavaScript that executes when any administrator views the affected invoice or visits the dashboard. Version 1.7.1 patches the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Invoiceplane | Invoiceplane | < 1.7.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-25595?
How severe is CVE-2026-25595?
How do I fix CVE-2026-25595?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-2559The Post SMTP plugin for WordPress is vulnerable to unauthor…5.3
- CVE-2026-25590The GLPI Inventory Plugin handles network discovery, invento…6.1
- CVE-2026-25591New API is a large language mode (LLM) gateway and artificia…6.5
- CVE-2026-25592Semantic Kernel is an SDK used to build, orchestrate, and de…9.9
- CVE-2026-25593OpenClaw is a personal AI assistant. Prior to 2026.1.20, an …8.4
- CVE-2026-25594InvoicePlane is a self-hosted open source application for ma…4.8
- CVE-2026-25596InvoicePlane is a self-hosted open source application for ma…4.8
- CVE-2026-25597PrestaShop is an open source e-commerce web application. Pri…5.3
- CVE-2026-25598Harden-Runner is a CI/CD security agent that works like an E…5.3
- CVE-2026-25599Missing authentication and clear‑text transmission of data f…6.3
- CVE-2026-2560A vulnerability has been found in kalcaddle kodbox up to 1.6…6.3
- CVE-2026-25600The PDBM application relies on a static, hard‑coded secret e…6.4
Are you affected by CVE-2026-25595?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
