CVE-2017-18217: Invoiceplane
Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.
An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and application/modules/quotes/views/view.php.
Affected products
- Invoiceplane Invoiceplane: before 1.5.5 (fixed in 1.5.5)
Published 2018-03-05. Last modified 2026-06-17.