CVE-2020-13476: Nchsoftware Express Invoice

Medium severity, CVSS 4.8. EPSS: 0.7% chance of exploitation in the next 30 days.

NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.

Affected products

  • Nchsoftware Express Invoice: from 8.06, up to and including 8.24

Published 2020-12-28. Last modified 2026-06-17.