CVE-2026-49850

CVE-2026-49850 published: InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without requiring POST and validating a C...

View full NVD advisory → ← Back to CVE watch