Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an administrator-controlled file-write capability. A malicious PHP file placed in the directory is automatically trusted by Mdl_templates and can be selected as public_invoice_template. When a public invoice is rendered, the guest View controller includes the trusted file and executes it with web-server privileges. This issue is fixed in version 1.7.2-rc-1. | |
| Title | InvoicePlane: Remote Code Execution via Writable Templates Directory | |
| Weaknesses | CWE-693 CWE-732 CWE-98 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-25T16:03:39.888Z
Reserved: 2026-04-06T20:28:38.394Z
Link: CVE-2026-39353
No data.
Status : Received
Published: 2026-09-25T16:17:25.053
Modified: 2026-09-25T17:17:08.360
Link: CVE-2026-39353
No data.
OpenCVE Enrichment
Updated: 2026-09-25T19:00:15Z