CVE-2026-24744: InvoicePlane has a Stored Cross-Site Scripting (XSS) issue
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the Edit Invoices functions of InvoicePlane version 1.7.0. When editing invoices, the application does not validate user input at the invoicenumber parameter. Although administrator privileges are required to exploit it, this is still considered a critical vulnerability as it can cause actions such as unauthorized modification of application data, creation of persistent backdoors through stored malicious scripts, and full compromise of the application's integrity. Version 1.7.1 patches the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24744?
The severity of CVE-2026-24744 is classified as medium due to the Stored Cross-Site Scripting vulnerability present in InvoicePlane version 1.7.0.
How do I fix CVE-2026-24744?
To fix CVE-2026-24744, upgrade to a patched version of InvoicePlane that addresses the Stored Cross-Site Scripting vulnerability.
Which version of InvoicePlane is affected by CVE-2026-24744?
InvoicePlane version 1.7.0 is the affected version with the Stored Cross-Site Scripting vulnerability.
What are the potential impacts of CVE-2026-24744?
The potential impacts of CVE-2026-24744 include unauthorized access to sensitive information and the execution of malicious scripts on user browsers.
Is there a patch available for CVE-2026-24744?
Yes, there is a patch available in the subsequent releases of InvoicePlane to mitigate the Stored Cross-Site Scripting vulnerability.