CVE-2026-39372

CVE-2026-39372 published: InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores and serves uploaded image attachments without stripping EXIF metadata. When an administrator uploads an image through inv...

View full NVD advisory → ← Back to CVE watch