---
cve: "CVE-2026-39353"
severity: "CRITICAL"
cvss: 9.1
epss: "55.4%"
vendor: "InvoicePlane"
kev: false
exploited: false
published: "2026-09-25 16:17:25"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-30T18:34:52+02:00"
---

# CVE-2026-39353

> 9.1 CRITICAL · 🧪 PoC

## Beschreibung

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an administrator-controlled file-write capability. A malicious PHP file placed in the directory is automatically trusted by Mdl_templates and can be selected as public_invoice_template. When a public invoice is rendered, the guest View controller includes the trusted file and executes it with web-server privileges. This issue is fixed in version 1.7.2-rc-1.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- 00e599db25804024eb323cfb751349bf3b1d8e8a (Commit)
- 893e82488f5b94ccdf9ff6fcf5a33dc188c9c98b (Commit)

## Referenzen

- <https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-v735-2x3r-gwpp>
- <https://github.com/InvoicePlane/InvoicePlane/pull/1536>
- <https://github.com/InvoicePlane/InvoicePlane/commit/00e599db25804024eb323cfb751349bf3b1d8e8a>
- <https://github.com/InvoicePlane/InvoicePlane/releases/tag/v1.7.2-rc-1>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-39353) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
