VendorsInvoice Ninjainvoice_ninjaany version
Vulnerabilities

Invoice Ninja Invoice Ninja any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-33898
In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to deserialize arbitrary PHP classes. In certain contexts, this can result in remote code execution. The attacker's input must be hosted at http://www.geoplugin.net (cleartext HTTP), and thus a successful attack requires spoofing that site or obtaining control of it.
Published 2021-06-06 · Modified
8.1EPSS 0.018
CVE-2021-3977
Cross-site Scripting (XSS) - Stored in invoiceninja/invoiceninja
Published 2021-12-24 · Modified
6.5EPSS 0.006
CVE-2026-33628
Invoice Ninja Denylist Bypass may Lead to Stored XSS via Invoice Line Items
Published 2026-03-26 · Analyzed
5.4EPSS 0.003
CVE-2026-33742
Invoice Ninja has Stored XSS via Markdown HTML Injection in Product Notes
Published 2026-03-26 · Analyzed
5.4EPSS 0.002