CVE-2026-85289: Invoiceplane
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane omits ensure_valid_post_request() from delete methods including Payments::delete(), Recurring::delete(), and User_clients::delete(). Although the routes require POST, they do not validate the request's CSRF token. An attacker can submit a cross-origin form through an authenticated administrator's browser to delete financial records and other application data. This issue is fixed in version 1.7.2.
Affected products
- Invoiceplane Invoiceplane: before 1.7.2 (fixed in 1.7.2)
Published 2026-09-25. Last modified 2026-09-28.