CVE-2026-85274: Invoiceplane
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Recurring::stop() as a state-changing GET route without CSRF token validation. When an authenticated administrator loads attacker-controlled content that requests /invoices/recurring/stop/{id}, the application stops the selected recurring invoice. An attacker can target multiple identifiers to interrupt recurring billing and cause financial loss. This issue is fixed in version 1.7.2.
Affected products
- Invoiceplane Invoiceplane: before 1.7.2 (fixed in 1.7.2)
Published 2026-09-25. Last modified 2026-09-28.