Remote Code Execution Vulnerability in InvoicePlane by InvoicePlane
CVE-2026-25548

9.1CRITICAL

Key Information:

Vendor
CVE Published:
18 February 2026

What is CVE-2026-25548?

A significant security vulnerability has been identified in InvoicePlane 1.7.0, which allows authenticated administrators to execute arbitrary commands on the server. This vulnerability arises from a series of attacks including Local File Inclusion and Log Poisoning. By manipulating the public_invoice_template setting, attackers can include compromised log files that contain malicious PHP code, posing a severe risk to the integrity of the system. The issue has been addressed in version 1.7.1, which provides critical patches to mitigate this risk. Users are strongly advised to update to the latest version to ensure the security of their applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

InvoicePlane <= 1.7.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.