CVE-2026-85293: InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mailer Forms

Published Sep 25, 2026
·
Updated

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-beta-1, InvoicePlane stores clientemail values without enforcing email syntax and renders them unescaped inside double-quoted value attributes in the invoice mailer form and quote mailer form. An administrator who can edit a client can store attribute-breaking input, and, when the mailer is configured, JavaScript executes when another authenticated administrator opens the related mailer page. The script runs in the InvoicePlane origin and can perform same-origin actions with the victim's session. This issue is fixed in version 1.7.2.

Affected Software

1 affected component
InvoicePlane InvoicePlane=1.7.2-beta-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade InvoicePlane to a version that resolves this vulnerability.

    Fixed in 1.7.2

Event History

Sep 25, 2026
CVE Published
via MITRE·03:29 PM
Data Sourced
via MITRE·03:29 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

InvoicePlane 1.7.2-beta-1 installations are exposed where an administrator can edit client records and another authenticated administrator can open the related invoice or quote mailer page. Exploitation requires the mailer to be configured.

2

What does an attacker need to exploit it?

The attacker needs administrator-level access that permits editing a client, plus the ability to set a client_email value containing attribute-breaking input. A separate authenticated administrator must then open the affected mailer page.

3

What is the impact after successful exploitation?

JavaScript executes in the InvoicePlane origin with the victim administrator's session. It can perform same-origin actions available to that victim.

4

How can I tell whether I may be affected?

Check whether the deployment is running version 1.7.2-beta-1 and whether invoice or quote mailer functionality is configured. Review client_email fields for values that do not conform to expected email syntax, especially values containing quote characters or HTML-like input.

5

What should I do if I cannot patch immediately?

Restrict administrator access to client editing and avoid opening invoice or quote mailer pages for clients whose email values have not been reviewed. Validate and clean existing client_email values to ensure they contain only valid email addresses.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203