Where
-Infinity
0

fossbilling fossbillingFOSSBilling: Downloadable product files can be overwritten through filename collisions

Risk 39
Severity
5.1
First published (updated )

fossbilling fossbillingFOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint

Risk 33
Severity
6.9
First published (updated )

fossbilling fossbillingFOSSBilling's missing order-state validation allows clients to read and reset API key secrets for non-active orders

Risk 62
Severity
8.6
First published (updated )

fossbilling fossbillingFOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints

Risk 79
Severity
8.7
First published (updated )

fossbilling fossbillingFOSSBilling: Unverified clients can access client-area pages when email confirmation is required

Risk 26
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

fossbilling fossbillingFOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literal

Risk 29
Severity
4.8
First published (updated )

fossbilling fossbillingFOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data

Risk 15
Severity
2.3
First published (updated )

fossbilling fossbillingFOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpayment

Risk 15
Severity
2.3
First published (updated )

fossbilling fossbillingFOSSBilling has race condition in cart checkout that bypasses promo code usage limits

Risk 33
Severity
6.9
First published (updated )

fossbilling fossbillingFOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code use

Risk 33
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

fossbilling fossbillingFOSSBilling has improper SQL neutralization in `Massmailer` recipient filters

Risk 36
Severity
6.9
First published (updated )

fossbilling fossbillingFOSSBilling has an unauthenticated payment bypass via IPN callback forgery

Risk 49
Severity
9.2
First published (updated )

fossbilling fossbillingFOSSBilling: Authentication bypass allows unauthenticated administrator creation

Risk 84
Severity
9.3
First published (updated )

fossbilling fossbillingFOSSBilling: IDOR in Servicecustom Client API allows cross-client data access

Risk 40
Severity
7.1
First published (updated )

fossbilling fossbillingFOSSBilling: Broken Authorization in Client Transaction and Order Listings

Risk 40
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

fossbilling fossbillingFOSSBilling: IDOR Vulnerability in Support Ticket Creation

Risk 24
Severity
5.1
First published (updated )

fossbilling fossbillingFOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin Functions

Risk 87
Severity
10
First published (updated )

fossbilling fossbillingFOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE

Risk 75
Severity
9.4
First published (updated )

fossbilling fossbillingFOSSBilling's password reset confirmation endpoint lacks rate limiting

Risk 27
Severity
6.3
First published (updated )

fossbilling fossbillingFOSSBilling has an open redirect via administrator-configured redirect targets

Risk 22
Severity
4.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

fossbilling fossbillingFOSSBilling version exposed via asset cache buster

Risk 33
Severity
6.9
First published (updated )

fossbilling fossbillingOpen Redirect in alextselegidis/easyappointments

Risk 46
Severity
6.3
First published (updated )

fossbilling fossbillingCross-site Scripting (XSS) - Reflected in fossbilling/fossbilling

Risk 38
Severity
6.1
First published (updated )

fossbilling fossbillingImproper Neutralization of Formula Elements in a CSV File in fossbilling/fossbilling

Risk 71
Severity
8
First published (updated )

fossbilling fossbillingUnrestricted Upload of File with Dangerous Type in fossbilling/fossbilling

Risk 79
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

fossbilling fossbillingSQL Injection in fossbilling/fossbilling

Risk 86
Severity
9.8
First published (updated )

fossbilling fossbillingSession Fixation in fossbilling/fossbilling

Risk 51
Severity
5.4
First published (updated )

fossbilling fossbillingCode Injection in fossbilling/fossbilling

Risk 65
Severity
7.2
First published (updated )

fossbilling fossbillingBusiness Logic Errors in fossbilling/fossbilling

Risk 38
Severity
6.5
First published (updated )

fossbilling fossbillingInsufficient Granularity of Access Control in fossbilling/fossbilling

Risk 33
Severity
5.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203