CVE-2024-56975: Invoiceplane
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller.
Affected products
- Invoiceplane Invoiceplane: before 1.6.2 (fixed in 1.6.2)
Published 2025-03-28. Last modified 2026-06-17.