CVE-2025-0474: Invoice Ninja
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56 through 5.11.23.
Affected products
- Invoice Ninja Invoice Ninja: from 5.8.56, up to and including 5.11.23
Published 2025-01-14. Last modified 2026-07-14.