CVE-2026-26281: InvoicePlane has Stored Cross-Site Scripting (XSS) Issue in Sumex Invoice View
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A stored cross-site scripting (XSS) vulnerability in the Sumex invoice view allows an authenticated user with client and invoice management privileges to execute arbitrary JavaScript in the browser of any user viewing the invoice. This can lead to session hijacking, data theft, or other malicious actions on behalf of the victim user. Version 1.7.1 patches the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26281?
The severity of CVE-2026-26281 is classified as moderate due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2026-26281?
To fix CVE-2026-26281, update InvoicePlane to version 1.7.2 or later, where the vulnerability has been addressed.
Who is affected by CVE-2026-26281?
Any authenticated user of InvoicePlane versions prior to 1.7.2 could be affected by CVE-2026-26281.
What type of vulnerability is CVE-2026-26281?
CVE-2026-26281 is a stored cross-site scripting (XSS) vulnerability.
How can attackers exploit CVE-2026-26281?
Attackers can exploit CVE-2026-26281 by injecting malicious scripts through the Sumex invoice view, which can execute in the context of another user's session.