CVE-2026-29925: Invoiceninja Invoice Ninja
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.
Affected products
- Invoiceninja Invoice Ninja: version 5.12.46 only; version 5.12.48 only
Published 2026-03-30. Last modified 2026-06-17.