NIXPKGS-2026-0282
GitHub issue
published on 19 Feb 2026
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
InvoicePlane has Stored XSS via Invoice Number in Invoice View and Dashboard
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Invoice Number field. An authenticated administrator can inject malicious JavaScript that executes when any administrator views the affected invoice or visits the dashboard. Version 1.7.1 patches the issue.
Affected products
InvoicePlane
- ==<= 1.7.0
Matching in nixpkgs
pkgs.invoiceplane
Self-hosted open source application for managing your invoices, clients and payments
Package maintainers
-
@onny Jonas Heinrich <onny@project-insanity.org>