File Upload Vulnerability in Invoice Ninja by Invoice Ninja
CVE-2025-10009
What is CVE-2025-10009?
The Invoice Ninja application contains a file upload vulnerability located in the admin 'Restore' function. This flaw allows attackers with valid admin credentials to upload malicious .php files. Once these files are successfully uploaded to the server, they can execute arbitrary code, potentially compromising the integrity and security of the application and its data. It is crucial for administrators to apply the latest updates and better secure their environments against such threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Invoice Ninja 5 Linux 5.11.41 <= 5.11.72
Invoice Ninja 5 Linux 5.11.73
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
