CVE-2026-39353

CVE-2026-39353 published: InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an administrator-contro...

View full NVD advisory → ← Back to CVE watch