CVE-2026-25595: InvoicePlane has Stored XSS via Invoice Number in Invoice View and Dashboard
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Invoice Number field. An authenticated administrator can inject malicious JavaScript that executes when any administrator views the affected invoice or visits the dashboard. Version 1.7.1 patches the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25595?
CVE-2026-25595 is classified as a high severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2026-25595?
To fix CVE-2026-25595, upgrade InvoicePlane to version 1.7.1 or later, which contains the necessary security updates.
What is the impact of CVE-2026-25595 on my InvoicePlane installation?
The impact of CVE-2026-25595 can allow attackers to inject malicious scripts into the Invoice Number field, potentially compromising user data.
Who is affected by CVE-2026-25595?
CVE-2026-25595 affects users of InvoicePlane versions prior to 1.7.1.
Is there a way to prevent CVE-2026-25595 if I cannot update immediately?
If you cannot update immediately, consider implementing input validation and output encoding to mitigate the XSS risk until you can apply the update.