CVE-2026-33639 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for ip_tax_rates in Settings::index() without strict integer validation. A crafted setting value can add clauses to the schema-changing statement and remove or alter required database columns. The resulting schema corruption can p
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for ip_tax_rates in Settings::index() without strict integer validation. A crafted setting value can add clauses to the schema-changing statement and remove or alter required database columns. The resulting schema corruption can permanently modify financial data structures and make the application unavailable. This vulnerability is fixed in 1.7.2.
- 🔗 github.com/InvoicePlane/InvoicePlane/security/adviso…
- 🔗 github.com/InvoicePlane/InvoicePlane/pull/1481
- 🔗 github.com/InvoicePlane/InvoicePlane/pull/1488
- 🔗 github.com/InvoicePlane/InvoicePlane/commit/8fe41750…
- 🔗 github.com/InvoicePlane/InvoicePlane/commit/efec2d28…
- 🔗 github.com/InvoicePlane/InvoicePlane/commit/fca7792a…
- 🔗 github.com/InvoicePlane/InvoicePlane/releases/tag/v1…
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-15 | 2026-09-28 |
|---|---|---|
| ≥90 % | 0 | 299 |
| ≥50 % | 0 | 958 |
| ≥10 % | 0 | 3 |
| <10 % | 300 | 250 |
CVE-2026-33639 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for ip_tax_rates in Settings::index() without strict integer validation. A crafted setting value can add clauses to the schema-changing statement and remove or alter required database columns. The resulting schema corruption can p
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for ip_
Noch keine Analyse zu CVE-2026-33639
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.