Cross-Site Request Forgery Vulnerability in InvoicePlane Application
CVE-2026-49850

7.5HIGH

Key Information:

Vendor
CVE Published:
25 September 2026

What is CVE-2026-49850?

The InvoicePlane application, a self-hosted platform for managing invoices and payments, has a security issue whereby it exposes critical state-changing functions without proper validation. Specifically, the Invoices::delete() and Invoices::delete_invoice_tax() routes can be exploited under certain conditions, allowing attackers to leverage unauthorized content to delete financial records. This vulnerability essentially enables a malicious actor to manipulate data within the application without the administrator's consent. The issue has been addressed in version 1.7.2 of InvoicePlane.

Affected Version(s)

InvoicePlane < 1.7.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.