CVE-2025-0474: Invoice Ninja

High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56 through 5.11.23.

Affected products

  • Invoice Ninja Invoice Ninja: from 5.8.56, up to and including 5.11.23

Published 2025-01-14. Last modified 2026-07-14.