CVE-2026-49850: Invoiceplane
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without requiring POST and validating a CSRF token. When an authenticated administrator loads attacker-controlled content that requests an affected route, the application can delete an invoice or invoice tax record. The cross-origin action can remove financial data without the administrator's intent. This issue is fixed in version 1.7.2.
Affected products
- Invoiceplane Invoiceplane: before 1.7.2 (fixed in 1.7.2)
Published 2026-09-25. Last modified 2026-09-28.