Vulnerabilities > Invoiceplane > Invoiceplane > 1.4.0

DATE CVE VULNERABILITY TITLE RISK
2024-12-16 CVE-2024-12667 Insufficient Session Expiration vulnerability in Invoiceplane
A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic.
network
high complexity
invoiceplane CWE-613
5.9
2018-03-05 CVE-2017-18217 Cross-site Scripting vulnerability in Invoiceplane
An issue was discovered in InvoicePlane before 1.5.5.
network
low complexity
invoiceplane CWE-79
6.1
2018-02-09 CVE-2017-1000508 Cross-site Scripting vulnerability in Invoiceplane
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code .
network
low complexity
invoiceplane CWE-79
6.1