Cross-Site Request Forgery Vulnerability in InvoicePlane by InvoicePlane
CVE-2026-85289

6.5MEDIUM

Key Information:

Vendor
CVE Published:
25 September 2026

What is CVE-2026-85289?

InvoicePlane, a self-hosted open-source application for managing invoices and payments, is susceptible to a cross-site request forgery vulnerability in versions prior to 1.7.2. The application lacks proper validation of CSRF tokens in its delete methods for Payments, Recurring, and User_clients, allowing authenticated attackers to exploit this oversight. By submitting a malicious form through an authenticated administrator's browser, attackers could delete sensitive financial records and other critical application data. This vulnerability has been resolved in version 1.7.2, emphasizing the importance of keeping software updated to safeguard against such attacks.

Affected Version(s)

InvoicePlane < 1.7.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.