CVE-2025-67084: Invoiceplane
Critical severity, CVSS 9.9. EPSS: 0.5% chance of exploitation in the next 30 days.
File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).
Affected products
- Invoiceplane Invoiceplane: before 1.6.4 (fixed in 1.6.4)
Published 2026-01-15. Last modified 2026-06-17.