Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-85274

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Sep 25, 2026
Vendor unknown

Description

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Recurring::stop() as a state-changing GET route without CSRF token validation. When an authenticated administrator loads attacker-controlled content that requests /invoices/recurring/stop/{id}, the application stops the selected recurring invoice. An attacker can target multiple identifiers to interrupt recurring billing and cause financial loss. This issue is fixed in version 1.7.2.

References