InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Invoice Number field. An authenticated administrator can inject malicious JavaScript that executes when any administrator views the affected invoice or visits the dashboard. Version 1.7.1 patches the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Invoice Number field. An authenticated administrator can inject malicious JavaScript that executes when any administrator views the affected invoice or visits the dashboard. Version 1.7.1 patches the issue. | |
| Title | InvoicePlane has Stored XSS via Invoice Number in Invoice View and Dashboard | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-18T22:52:27.047Z
Reserved: 2026-02-03T01:02:46.717Z
Link: CVE-2026-25595
No data.
Status : Received
Published: 2026-02-18T23:16:19.910
Modified: 2026-02-18T23:16:19.910
Link: CVE-2026-25595
No data.
OpenCVE Enrichment
No data.