VendorsInvoice Ninjainvoice_ninjaall versions
Vulnerabilities

Invoice Ninja Invoice Ninja

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2021-33898
In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to deserialize arbitrary PHP classes. In certain contexts, this can result in remote code execution. The attacker's input must be hosted at http://www.geoplugin.net (cleartext HTTP), and thus a successful attack requires spoofing that site or obtaining control of it.
Published 2021-06-06 · Modified
8.1EPSS 0.018
CVE-2026-29925
Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.
Published 2026-03-30 · Analyzed
7.7EPSS 0.004
CVE-2021-3977
Cross-site Scripting (XSS) - Stored in invoiceninja/invoiceninja
Published 2021-12-24 · Modified
6.5EPSS 0.006
CVE-2017-1000466
Invoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page, which can result in disruption of service and execution of javascript code.
Published 2018-01-03 · Modified
5.4EPSS 0.008
CVE-2026-33628
Invoice Ninja Denylist Bypass may Lead to Stored XSS via Invoice Line Items
Published 2026-03-26 · Analyzed
5.4EPSS 0.003
CVE-2026-33742
Invoice Ninja has Stored XSS via Markdown HTML Injection in Product Notes
Published 2026-03-26 · Analyzed
5.4EPSS 0.002