Cross-Site Scripting Vulnerability in InvoiceNinja by Invoice Ninja
CVE-2026-71233

8.7HIGH

Key Information:

Vendor
CVE Published:
5 August 2026

What is CVE-2026-71233?

A notable cross-site scripting vulnerability exists in InvoiceNinja v5-stable, where the 'terms' field in invoices is rendered without proper HTML sanitization. This occurs when authenticated users with rights to create invoices can inject malicious HTML or JavaScript via a REST API endpoint. The unfiltered content can execute code in clients' browsers when they view invoices, potentially leading to session cookie theft and unauthorized account access. This vulnerability highlights the importance of sanitizing user inputs to prevent XSS attacks, particularly in user-facing applications.

Affected Version(s)

invoiceninja 5.0.0

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alibek baxtiyarov
.