Search Results (42 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2017-18217 1 Invoiceplane 1 Invoiceplane 2024-11-21 N/A
An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and application/modules/quotes/views/view.php.
CVE-2017-1000508 1 Invoiceplane 1 Invoiceplane 2024-11-21 N/A
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later.