CVE-2025-67084: Critical severity InvoicePlane InvoicePlane vulnerability
Published Jan 15, 2026
·Updated
File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).
Affected Software
2 affected components
InvoicePlane InvoicePlane<=1.6.3
InvoicePlane InvoicePlane<1.6.4
Event History
Jan 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67084?
CVE-2025-67084 has a high severity rating due to its potential for Remote Code Execution.
2
How do I fix CVE-2025-67084?
To fix CVE-2025-67084, update InvoicePlane to version 1.6.4 or later immediately.
3
Who is affected by CVE-2025-67084?
CVE-2025-67084 affects users of InvoicePlane version 1.6.3 and below.
4
What can an attacker do with CVE-2025-67084?
An attacker can upload arbitrary PHP files, leading to Remote Code Execution on the server.
5
Is CVE-2025-67084 a zero-day vulnerability?
CVE-2025-67084 could be considered a zero-day vulnerability until a patch is applied.