Known Vulnerabilities for Invoices by Ithemes
Listed below are 1 of the newest known vulnerabilities associated with "Invoices" by "Ithemes".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-101139 json | A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4. This impacts an unknown function of the file /admin/s... | Not Provided | 2026-09-28 | 2026-09-29 |
| CVE-2026-100392 json | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::... | Not Provided | 2026-09-28 | 2026-09-29 |
| CVE-2026-100371 json | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, an auth... | Not Provided | 2026-09-28 | 2026-09-29 |
| CVE-2026-97078 json | Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions. | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-94432 json | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Inse... | Not Provided | 2026-10-02 | 2026-10-03 |
| CVE-2026-94039 json | A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/in... | Not Provided | 2026-09-20 | 2026-09-21 |
| CVE-2026-92457 json | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that... | Not Provided | 2026-09-16 | 2026-09-21 |
| CVE-2026-92244 json | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billin... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-88003 json | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePl... | Not Provided | 2026-09-25 | 2026-09-28 |
| CVE-2026-87797 json | The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a priva... | Not Provided | 2026-09-12 | 2026-09-12 |