CVE-2026-25594: InvoicePlane has Stored XSS via Family Name in Product Form
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Family Name field. The familyname value is rendered without HTML encoding inside the family dropdown on the product form. When an administrator creates a family with a malicious name, the payload executes in the browser of any administrator who visits the product form. Version 1.7.1 patches the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25594?
CVE-2026-25594 is classified as a high severity vulnerability due to the risk of stored XSS attacks.
How do I fix CVE-2026-25594?
To fix CVE-2026-25594, upgrade InvoicePlane to version 1.7.1 or later.
What types of vulnerability does CVE-2026-25594 represent?
CVE-2026-25594 represents a Stored Cross-Site Scripting (XSS) vulnerability.
Which versions of InvoicePlane are affected by CVE-2026-25594?
CVE-2026-25594 affects InvoicePlane versions prior to 1.7.1.
What can attackers do with CVE-2026-25594?
Attackers can exploit CVE-2026-25594 to execute malicious scripts in the context of users' browsers.