CVE-2026-25596: InvoicePlane has Stored XSS via Product Unit Name in Invoice Item List
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Product Unit Name fields. An authenticated administrator can inject malicious JavaScript that executes when any administrator views an invoice containing a product with the malicious unit. Version 1.7.1 patches the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25596?
CVE-2026-25596 is classified as a medium severity vulnerability due to its potential for Stored XSS attacks.
How do I fix CVE-2026-25596?
To fix CVE-2026-25596, upgrade InvoicePlane to version 1.7.1 or later, which resolves the vulnerability.
What types of attacks can CVE-2026-25596 enable?
CVE-2026-25596 allows attackers to perform Stored Cross-Site Scripting, potentially compromising user accounts.
Who is affected by CVE-2026-25596?
CVE-2026-25596 affects users of InvoicePlane versions prior to 1.7.1.
Is authentication required to exploit CVE-2026-25596?
Yes, exploitation of CVE-2026-25596 requires authentication as it targets the Product Unit Name field in the Invoice Item List.