CVE-2026-33639: InvoicePlane permits DDL injection through tax_rate_decimal_places

Published Sep 25, 2026
·
Updated

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled taxratedecimalplaces setting into an ALTER TABLE statement for iptaxrates in Settings::index() without strict integer validation. A crafted setting value can add clauses to the schema-changing statement and remove or alter required database columns. The resulting schema corruption can permanently modify financial data structures and make the application unavailable. This vulnerability is fixed in 1.7.2.

Affected Software

1 affected component
InvoicePlane InvoicePlane<1.7.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade InvoicePlane to a version that resolves this vulnerability.

    Fixed in 1.7.2

Event History

Sep 25, 2026
CVE Published
via MITRE·03:36 PM
Data Sourced
via MITRE·03:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this vulnerability?

An attacker needs administrator-level access to change the tax_rate_decimal_places setting. It is therefore most relevant where administrative accounts are compromised, improperly shared, or accessible to untrusted users.

2

Which deployments are affected?

InvoicePlane versions prior to 1.7.2 are affected. The vulnerable path is the administrator-controlled tax_rate_decimal_places setting used while changing the ip_tax_rates table schema.

3

What is the impact of successful exploitation?

A crafted setting can inject additional clauses into an ALTER TABLE statement. This can remove or modify required database columns, permanently corrupt financial data structures, and make the application unavailable.

4

What should be done if upgrading cannot happen immediately?

Restrict access to administrator accounts and prevent untrusted users from changing tax_rate_decimal_places. Because exploitation can permanently alter the database schema, ensure current, tested database backups are available before administrators modify this setting.

5

How can administrators check for possible exploitation?

Review the ip_tax_rates schema for missing or unexpectedly altered columns and investigate recent changes to tax_rate_decimal_places. Database backups or schema records can help identify deviations from the expected structure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203