Cross-Site Request Forgery Vulnerability in InvoicePlane Application
CVE-2026-49850
7.5HIGH
What is CVE-2026-49850?
The InvoicePlane application, a self-hosted platform for managing invoices and payments, has a security issue whereby it exposes critical state-changing functions without proper validation. Specifically, the Invoices::delete() and Invoices::delete_invoice_tax() routes can be exploited under certain conditions, allowing attackers to leverage unauthorized content to delete financial records. This vulnerability essentially enables a malicious actor to manipulate data within the application without the administrator's consent. The issue has been addressed in version 1.7.2 of InvoicePlane.
Affected Version(s)
InvoicePlane < 1.7.2
