CVE-2026-29925: Invoiceninja Invoice Ninja

High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.

Affected products

  • Invoiceninja Invoice Ninja: version 5.12.46 only; version 5.12.48 only

Published 2026-03-30. Last modified 2026-06-17.