FOSSBilling
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 33 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 14, 2023 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →FOSSBilling: Downloadable product files can be overwritten through filename collisions
FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint
FOSSBilling's missing order-state validation allows clients to read and reset API key secrets for non-active orders
FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints
FOSSBilling: Unverified clients can access client-area pages when email confirmation is required
FOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literal
FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data
FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpayment
FOSSBilling has race condition in cart checkout that bypasses promo code usage limits
FOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code use
Monitor FOSSBilling in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.