InvoicePlane
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 42 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from November 17, 2017 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →InvoicePlane: Failure to Revoke Administrative Privileges After Role Downgrade
InvoicePlane: Missing CSRF Protection on State-Changing delete Actions
InvoicePlane permits local file inclusion through the e-invoice XML configuration identifier
InvoicePlane permits DDL injection through tax_rate_decimal_places
InvoicePlane: Remote Code Execution via Writable Templates Directory
InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mailer Forms
InvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Without Authorization Check
InvoicePlane: Missing CSRF Token Validation on Multiple Delete Endpoints
InvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-Depth)
InvoicePlane: Recurring Invoice State Change via GET Request Without CSRF Protection
Monitor InvoicePlane in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.