Stored Cross-Site Scripting Vulnerability in InvoicePlane by InvoicePlane
CVE-2026-24746
5.7MEDIUM
What is CVE-2026-24746?
InvoicePlane, an open-source application designed for invoice management, suffers from a Stored Cross-Site Scripting vulnerability within its Edit Quotes feature in version 1.7.0. This vulnerability can be exploited by users with administrative privileges, allowing them to inject malicious scripts that can alter application data, establish persistent backdoors, and potentially compromise the overall integrity of the application. The issue has been addressed in version 1.7.1.
Affected Version(s)
InvoicePlane = 1.7.0
