CVE-2026-85289

CVE-2026-85289 published: InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane omits ensure_valid_post_request() from delete methods including Payments::delete(), Recurring::delete(), and User_clients::delet...

View full NVD advisory → ← Back to CVE watch